Vulnerabilidades em VMware

239 resultados
Análise Vexday

Com 6 CVEs confirmadas em exploração ativa pelo CISA KEV, a VMware apresenta uma taxa de exploração 6 vezes acima da média geral do catálogo, sinal de que suas vulnerabilidades atraem atenção ofensiva desproporcional ao volume total de falhas catalogadas. A CVE-2023-34048, com EPSS de 0,9943, representa o caso mais crítico no momento — probabilidade de exploração próxima à máxima estimada pelo modelo, justificando tratamento prioritário em qualquer fila de remediação. A presença de 7 CVEs com PoC pública e 10 de severidade crítica amplia a superfície de risco concreto, especialmente considerando que 11 novas vulnerabilidades surgiram nos últimos 90 dias. O tipo de falha mais recorrente (CWE-79) sugere atenção persistente a controles de saída e sanitização em componentes de interface, mas o perfil geral de risco da VMware é dominado por falhas de maior impacto sistêmico com alto potencial de exploração.

CVE-2018-6962VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.EPSS 0.4%CVE-2026-22720HIGHVMware Aria Operations stored cross-site scripting vulnerabilityEPSS 0.4%CVE-2017-4903VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.EPSS 0.4%CVE-2017-4948VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TEPSS 0.4%CVE-2018-6963VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due toEPSS 0.4%CVE-2024-22266MEDIUMVMware Avi Load Balancer updates address multiple vulnerabilitiesEPSS 0.4%CVE-2026-41709LOWESX insufficient logging vulnerabilityEPSS 0.4%CVE-2025-22221MEDIUMVMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221)EPSS 0.4%CVE-2020-3970VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.4%CVE-2026-41723HIGHVMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)EPSS 0.4%CVE-2024-38833MEDIUMStored cross-site scripting vulnerability (CVE-2024-38833)EPSS 0.4%CVE-2018-6969VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may EPSS 0.4%CVE-2017-4932VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UEPSS 0.4%CVE-2017-4935VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability EPSS 0.4%CVE-2017-4898VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLEPSS 0.4%CVE-2017-4936VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability iEPSS 0.4%CVE-2017-4937VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability iEPSS 0.4%CVE-2019-5543For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware WorkstatiEPSS 0.4%CVE-2017-4913VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the TrueEPSS 0.4%CVE-2017-4925VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SGEPSS 0.4%