Home
HIGH: 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:HDefault status
affected
ESXi 8.0U3i, included in VCF 5.2.3.0 or 9.0.2 releases
unaffected
Description
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.
Problem types
CWE-822 Untrusted Pointer Dereference
Product status
ESXi 8.0U3i, included in VCF 5.2.3.0 or 9.0.2 releases
Credits
Reported through AMD Bug Bounty Program
References
www.amd.com/...es/product-security/bulletin/AMD-SB-2001.html