VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fusion | Vmware | * | 4.4 (excluding) |
Esxi | Vmware | 7.0-update_1 (including) | 7.0-update_1 (including) |
Esxi | Vmware | 7.0-update_2 (including) | 7.0-update_2 (including) |
Esxi | Vmware | 7.0-update_3 (including) | 7.0-update_3 (including) |