CVE-2024-22251

VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

10 Jun 2025, 19:33

Type Values Removed Values Added
References () https://www.vmware.com/security/advisories/VMSA-2024-0005.html - () https://www.vmware.com/security/advisories/VMSA-2024-0005.html - Vendor Advisory
First Time Apple macos
Vmware fusion
Vmware workstation
Vmware
Apple
CPE cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://www.vmware.com/security/advisories/VMSA-2024-0005.html - () https://www.vmware.com/security/advisories/VMSA-2024-0005.html -

01 Nov 2024, 20:35

Type Values Removed Values Added
CWE CWE-125
Summary
  • (es) VMware Workstation y Fusion contienen una vulnerabilidad de lectura fuera de los límites en el CCID USB (dispositivo de interfaz de tarjeta chip). Un actor malicioso con privilegios administrativos locales en una máquina virtual puede desencadenar una lectura fuera de los límites que conduzca a la divulgación de información.

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2025-06-10 19:33


NVD link : CVE-2024-22251

Mitre link : CVE-2024-22251

CVE.ORG link : CVE-2024-22251


JSON object : View

Products Affected

apple

  • macos

vmware

  • workstation
  • fusion
CWE
CWE-125

Out-of-bounds Read