{"id":55527,"date":"2024-03-07T14:06:10","date_gmt":"2024-03-07T14:06:10","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/35623\/VMware-Sandbox-Escape-Bugs-Are-So-Critical-Patches-Are-Released-For-End-Of-Life-Products.html"},"modified":"2024-03-07T14:06:10","modified_gmt":"2024-03-07T14:06:10","slug":"vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/","title":{"rendered":"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products"},"content":{"rendered":"<figure class=\"intro-image intro-left\"> <img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2022\/05\/cloud-computing-800x534.jpeg\" alt=\"VMware sandbox escape bugs are so critical, patches are released for end-of-life products\"><figcaption class=\"caption\">\n<div class=\"caption-credit\">Getty Images<\/div>\n<\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"> <a class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/security\/2024\/03\/vmware-issues-patches-for-critical-sandbox-escape-vulnerabilities\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">22<\/span> <\/a> <\/aside>\n<p> <!-- cache hit 75:single\/related:66bfffa80cff2df13594aaf059709461 --><!-- empty --><\/p>\n<p>VMware is urging customers to patch critical vulnerabilities that make it possible for hackers to break out of sandbox and hypervisor protections in all versions, including out-of-support ones, of VMware ESXi, Workstation, Fusion, and Cloud Foundation products.<\/p>\n<p>A constellation of four vulnerabilities\u2014two carrying severity ratings of 9.3 out of a possible 10\u2014are serious because they undermine the fundamental purpose of the VMware products, which is to run sensitive operations inside a virtual machine that\u2019s segmented from the host machine. VMware officials said that the prospect of a hypervisor escape warranted an immediate response under the company\u2019s <a href=\"https:\/\/www.vmware.com\/topics\/glossary\/content\/application-management.html\">IT Infrastructure Library<\/a>, a process usually abbreviated as ITIL.<\/p>\n<h2>\u201cEmergency change\u201d<\/h2>\n<p>\u201cIn ITIL terms, this situation qualifies as an emergency change, necessitating prompt action from your organization,\u201d the officials wrote in a <a href=\"https:\/\/core.vmware.com\/resource\/vmsa-2024-0006-questions-answers#who-does-this-affect\">post<\/a>. \u201cHowever, the appropriate security response varies depending on specific circumstances.\u201d<\/p>\n<p>Among the specific circumstances, one concerns which vulnerable product a customer is using, and another is whether and how it may be positioned behind a firewall. A <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0006.html\">VMware advisory<\/a> included the following matrix showing how the vulnerabilities\u2014tracked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255\u2014affect each of the vulnerable products:<\/p>\n<table>\n<tbody>\n<tr>\n<th>Product<\/th>\n<th>Version<\/th>\n<th>Running On<\/th>\n<th>CVE Identifier<\/th>\n<th>CVSSv3<\/th>\n<th>Severity<\/th>\n<th>Fixed Version [1]<\/th>\n<th>Workarounds<\/th>\n<th>Additional Documentation<\/th>\n<\/tr>\n<tr>\n<td>ESXi<\/td>\n<td>8.0<\/td>\n<td>Any<\/td>\n<td>CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255<\/td>\n<td>8.4, 8.4, 7.9, 7.1<\/td>\n<td>critical<\/td>\n<td>ESXi80U2sb-23305545<\/td>\n<td>KB96682<\/td>\n<td>FAQ<\/td>\n<\/tr>\n<tr>\n<td>ESXi<\/td>\n<td>8.0 [2]<\/td>\n<td>Any<\/td>\n<td>CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255<\/td>\n<td>8.4, 8.4, 7.9, 7.1<\/td>\n<td>critical<\/td>\n<td>ESXi80U1d-23299997<\/td>\n<td>KB96682<\/td>\n<td>FAQ<\/td>\n<\/tr>\n<tr>\n<td>ESXi<\/td>\n<td>7.0<\/td>\n<td>Any<\/td>\n<td>CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255<\/td>\n<td>8.4, 8.4, 7.9, 7.1<\/td>\n<td>critical<\/td>\n<td>ESXi70U3p-23307199<\/td>\n<td>KB96682<\/td>\n<td>FAQ<\/td>\n<\/tr>\n<tr>\n<td>Workstation<\/td>\n<td>17.x<\/td>\n<td>Any<\/td>\n<td>CVE-2024-22252, CVE-2024-22253, CVE-2024-22255<\/td>\n<td>9.3, 9.3, 7.1<\/td>\n<td>critical<\/td>\n<td>17.5.1<\/td>\n<td>KB96682<\/td>\n<td>None.<\/td>\n<\/tr>\n<tr>\n<td>Fusion<\/td>\n<td>13.x<\/td>\n<td>MacOS<\/td>\n<td>CVE-2024-22252, CVE-2024-22253, CVE-2024-22255<\/td>\n<td>9.3, 9.3, 7.1<\/td>\n<td>critical<\/td>\n<td>13.5.1<\/td>\n<td>KB96682<\/td>\n<td>None<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Three of the vulnerabilities affect the USB controller the products use to support peripheral devices such as keyboards and mice. The advisory describes the vulnerabilities as:<\/p>\n<p><b>CVE-2024-22252:<\/b> a use-after-free vulnerability in XHCI USB controller with a maximum severity range of 9.3 for Workstation\/Fusion and a base score of 8.4 for ESXi. Someone with local administrative privileges on a virtual machine can execute code as the virtual machine&#8217;s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox, whereas, on Workstation and Fusion, this could lead to code execution on the machine where Workstation or Fusion is installed.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p><b>CVE-2024-22253:<\/b> a use-after-free vulnerability in UHCI USB controller with a maximum severity rating of 9.3 for Workstation\/Fusion and a base score of 8.4 for ESXi. Exploitation requirements and outcomes are the same as for CVE-2024-22252.<\/p>\n<p><b>CVE-2024-22254:<\/b> an out-of-bounds write vulnerability with a maximum severity base score of 7.9. This vulnerability makes it possible for someone with privileges within the VMX process to trigger an out-of-bounds write, leading to a sandbox escape.<\/p>\n<p><b>CVE-2024-22255:<\/b> an information disclosure vulnerability in the UHCI USB controller with a maximum CVSSv3 base score of 7.1. Someone with administrative access to a virtual machine can exploit it to leak memory from the vmx process.<\/p>\n<p>Broadcom, the VMware parent company, is urging customers to patch vulnerable products. As a workaround, users can remove USB controllers from vulnerable virtual machines, but Broadcom stressed that this measure could degrade virtual console functionality and should be viewed as only a temporary solution. In an <a href=\"https:\/\/kb.vmware.com\/s\/article\/96682\">article<\/a> explaining how to remove a USB controller, officials wrote:<\/p>\n<blockquote>\n<p>The workaround is to remove all USB controllers from the Virtual Machine. As a result, USB passthrough functionality will be unavailable.<\/p>\n<p>In addition, virtual\/emulated USB devices, such as VMware virtual USB stick or dongle, will not be available for use by the virtual machine. In contrast, the default keyboard\/mouse as input devices are not affected as they are, by default, not connected through USB protocol but have a driver that does software device emulation in the guest OS.<\/p>\n<p><b>IMPORTANT:<\/b><br \/>Certain guest operating systems, including Mac OS, do not support using a PS\/2 mouse and keyboard. These guest operating systems will be left without a mouse and keyboard without a USB controller.<\/p>\n<\/blockquote>\n<p>VMware said it isn\u2019t aware of any evidence that any of the vulnerabilities are under active exploitation.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/35623\/VMware-Sandbox-Escape-Bugs-Are-So-Critical-Patches-Are-Released-For-End-Of-Life-Products.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":55528,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[3967],"class_list":["post-55527","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerflawpatch"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-07T14:06:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2022\/05\/cloud-computing-800x534.jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products\",\"datePublished\":\"2024-03-07T14:06:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/\"},\"wordCount\":699,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg\",\"keywords\":[\"headline,hacker,flaw,patch\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/\",\"name\":\"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg\",\"datePublished\":\"2024-03-07T14:06:10+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg\",\"width\":800,\"height\":534},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,flaw,patch\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerflawpatch\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/","og_locale":"en_US","og_type":"article","og_title":"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-03-07T14:06:10+00:00","og_image":[{"url":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2022\/05\/cloud-computing-800x534.jpeg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products","datePublished":"2024-03-07T14:06:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/"},"wordCount":699,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg","keywords":["headline,hacker,flaw,patch"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/","url":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/","name":"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg","datePublished":"2024-03-07T14:06:10+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products.jpg","width":800,"height":534},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/vmware-sandbox-escape-bugs-are-so-critical-patches-are-released-for-end-of-life-products\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,flaw,patch","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerflawpatch\/"},{"@type":"ListItem","position":3,"name":"VMware Sandbox Escape Bugs Are So Critical, Patches Are Released For End-Of-Life Products"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=55527"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55527\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/55528"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=55527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=55527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=55527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}