Vmware
Vmware Workstation: vulnerabilidades y CVE
Vmware Workstation tiene 222 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 8 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE222
Últimos 12 meses4
Críticas8
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-22224 | Alta (8.2) | 1.6% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this… |
| CVE-2025-22226 | Media (6) | 1.8% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41703 | Alta (7.6) | 0.43% | — | 30 jul 2026 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more… |
| CVE-2026-22717 | Baja (2.7) | 0.17% | — | 27 feb 2026 | Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where… |
| CVE-2026-22716 | Media (5) | 0.16% | — | 27 feb 2026 | Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes. |
| CVE-2026-22715 | Media (5.9) | 0.21% | — | 26 feb 2026 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network… |
| CVE-2025-41239 | Alta (7.1) | 2.9% | — | 15 jul 2025 | VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a… |
| CVE-2025-41238 | Crítica (9.3) | 0.45% | — | 15 jul 2025 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on… |
| CVE-2025-41237 | Crítica (9.3) | 0.45% | — | 15 jul 2025 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a… |
| CVE-2025-41236 | Crítica (9.3) | 2.5% | — | 15 jul 2025 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual… |
| CVE-2025-41227 | Media (5.5) | 0.16% | — | 20 may 2025 | VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit… |
| CVE-2025-22226 | Media (6) | 1.8% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit… |
| CVE-2025-22224 | Alta (8.2) | 1.6% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this… |
| CVE-2024-22273 | Alta (7.8) | 0.17% | — | 21 may 2024 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to… |
| CVE-2024-22270 | Media (6) | 0.51% | — | 14 may 2024 | VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able… |
| CVE-2024-22269 | Media (6) | 0.51% | — | 14 may 2024 | VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged… |
| CVE-2024-22268 | Media (6.5) | 0.50% | — | 14 may 2024 | VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to… |
| CVE-2024-22267 | Alta (8.2) | 0.68% | — | 14 may 2024 | VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the… |
| CVE-2024-22255 | Alta (7.1) | 2.3% | — | 5 mar 2024 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to… |
| CVE-2024-22253 | Media (6.7) | 0.65% | — | 5 mar 2024 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code… |
| CVE-2024-22252 | Media (6.7) | 3.5% | — | 5 mar 2024 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code… |
| CVE-2024-22251 | Media (4.4) | 0.23% | — | 29 feb 2024 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an… |
| CVE-2023-34044 | Media (6) | 0.20% | — | 20 oct 2023 | VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A… |
| CVE-2023-20870 | Media (6) | 0.37% | — | 25 abr 2023 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. |
| CVE-2023-20869 | Alta (8.2) | 2.0% | — | 25 abr 2023 | VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. |
| CVE-2023-20872 | Alta (8.8) | 0.87% | — | 25 abr 2023 | VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. |
| CVE-2023-20854 | Alta (8.4) | 0.29% | — | 3 feb 2023 | VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of… |
| CVE-2022-31705 | Alta (8.2) | 1.1% | — | 14 dic 2022 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue… |
| CVE-2022-22983 | Media (5.9) | 0.30% | — | 10 ago 2022 | VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the… |
| CVE-2021-22041 | Media (6.7) | 0.57% | — | 16 feb 2022 | VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as… |
| CVE-2022-22938 | Media (6.5) | 0.36% | — | 28 ene 2022 | VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A… |
| CVE-2021-22045 | Alta (7.8) | 4.7% | — | 4 ene 2022 | VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.