Critical severity9.3NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026
CVE-2024-22267
CVE-2024-22267
Description
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*range: >=17.0.0,<17.5.2
- (no CPE)
- NA/VMware Workstationv5Range: 17.x
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.