VMware fixed critical VM Escape bug demonstrated at Geekpwn hacking contest

VMware fixed three flaws in multiple products, including a virtual machine escape issue exploited at the GeekPwn 2022 hacking competition.

VMware addressed three vulnerabilities in multiple products, including a virtual machine escape flaw, tracked as CVE-2022-31705, that was exploited at the GeekPwn 2022 hacking competition.

A working exploit for the CVE-2022-31705 vulnerability was demonstrated by Ant Security researcher Yuhao Jiang during the Geekpwn, a hacking contest run by the Tencent Keen Security Lab.

Here is my demo of the VM escape exploit on the latest version of VMware Fusion along with ESXi and Workstation. It was used to participate in GeekPwn 2022 and won the championship. pic.twitter.com/Ze2rtCVAsv— Danis Jiang (@danis_jiang) November 14, 2022The CVE-2022-31705 vulnerability (CVSSv3 base score of 9.3) is a heap out-of-bounds write issue in the USB 2.0 controller (EHCI).

“VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI)” reads the advisory published by the virtualization giant. “A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.”

The company also addressed a command injection and directory traversal security vulnerabilities, respectively tracked as CVE-2022-31702 and CVE-2022-31703, impacting the VMware vRealize Network Insight (vRNI) solution. Below are the details for the flaws:

VMware vRealize Network Insight (vRNI) command injection vulnerability (CVE-2022-31702) – “vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API.” states the advisory. “A malicious actor with network access to the vRNI REST API can execute commands without authentication.”
VMware vRealize Network Insight (vRNI) contains a directory traversal vulnerability (CVE-2022-31703) – “vRealize Network Insight (vRNI) directory traversal vulnerability in vRNI REST API.” reads the advisory. “A malicious actor with network access to the vRNI REST API can read arbitrary files from the server.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}
Pierluigi Paganini

(SecurityAffairs – hacking, VMware)

The post VMware fixed critical VM Escape bug demonstrated at Geekpwn hacking contest appeared first on Security Affairs.