VMware ESXi
cpe:2.3:a:vmware:vsphere_esxi:*:*:*:*:*:*:*, +1 more
- >= 8.0, < 8.0 U3e
- >= 7.0, < 7.0 U3v
A denial-of-service vulnerability has been identified in VMware ESXi, Workstation, and Fusion. This issue arises from certain guest options, allowing a malicious actor with non-administrative privileges within a guest operating system to exhaust the memory of the host process. This memory exhaustion can lead to a denial-of-service condition, causing disruptions in service or performance.
Exploitation of this vulnerability can cause memory exhaustion on the host process, leading to a denial-of-service condition.
Users can upgrade to VMware Workstation version 17.6.3 or VMware Fusion version 13.6.3. For VMware ESXi, the update to version 8.0 U3e or 7.0 U3v is recommended. VMware Cloud Foundation users should refer to the async patching guide available on the Broadcom Knowledge Base.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.