VMware fixes three zero-day bugs exploited at Pwn2Own 2024
ID: 3393956d-c499-509b-bf00-48dfcb3f50fd
STIX ID: report--3393956d-c499-509b-bf00-48dfcb3f50fd
Feed Name: Bleeping Computer
Threat Score
VMware patched four vulnerabilities in Workstation and Fusion, including three zero-days demonstrated at Pwn2Own Vancouver 2024 that were chained to escape guest VMs and achieve code execution on the host (notably CVE-2024-22267). Two other high-severity issues permit hypervisor memory disclosure, and a shader heap overflow can cause DoS when 3D is enabled; VMware published advisories and a workaround to disable Bluetooth sharing for mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
