The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →VMware security advisory VMSA-2022-0033 addresses CVE-2022-31705, a heap out-of-bounds write in the emulated USB 2.0 EHCI controller. A guest user with local administrator privileges could exploit it to run code as the VMX process on the host. VMware published product-specific fixes on 13 December 2022; the impact differs between ESXi and desktop hypervisors.
What is CVE-2022-31705?
It is a vulnerability in VMware’s emulated USB 2.0 EHCI controller. Broadcom’s advisory describes the flaw as a heap out-of-bounds write. A malicious actor must already have local administrative privileges inside a virtual machine; the advisory does not describe an unauthenticated remote attack.
The potential result is execution of code as the host’s VMX process. The boundary of that impact varies by product:
- ESXi: VMware says exploitation is contained within the VMX sandbox.
- Workstation and Fusion: exploitation may lead to code execution on the machine where the hypervisor application is installed.
The advisory gives a maximum CVSS v3 base score of 9.3, but its product-specific entries differ: ESXi 7.0 and 8.0 are scored 5.9 (Moderate), while Workstation 16.x and Fusion 12.x are scored 9.3 (Critical). These are vendor severity scores, not measures of the chance that a particular system will be attacked or compromised. Read Broadcom’s VMware Security Advisory VMSA-2022-0033.
#1 Best Overall
What happened at GeekPwn 2022?
Broadcom’s advisory credits Yuhao Jiang and the GeekPwn 2022 organizers in connection with the report. A contemporaneous account by Security Affairs, published 14 December 2022, says Jiang demonstrated a working VM escape at the event and identifies him as an Ant Security researcher.
A competition demonstration is not evidence that criminals were exploiting the flaw in real-world attacks. The cited advisory and event coverage establish the vulnerability, its report, and the demonstration; they do not establish exploitation in the wild.
Rank #2
Which VMware versions did the December 2022 advisory list as affected?
The following entries reproduce the advisory’s historical response matrix. The fixed builds are the versions listed in that December 2022 advisory, not a claim that those builds are the latest available today.
| Product entry | Advisory score and severity | Fixed version listed | Workaround reference |
|---|---|---|---|
| ESXi 8.0 | 5.9, Moderate | ESXi80a-20842819 | KB87617 |
| ESXi 7.0 | 5.9, Moderate | ESXi70U3si-20841705 | KB87617 |
| Fusion 12.x on OS X | 9.3, Critical | 12.2.5 | KB79712 |
| Workstation 16.x | 9.3, Critical | 16.2.5 | KB79712 |
| Cloud Foundation 4.x/3.x using the ESXi component | Not stated in the advisory entry cited here | KB90336 | KB87617 |
| Fusion 13.x and Workstation 17.x | Marked unaffected in this advisory | Not applicable: marked unaffected | Not stated |
See the full VMSA-2022-0033 response matrix for the vendor’s entries and notes. The matrix applies to the products and versions it names; do not infer that every VMware product or release shares the same exposure or severity.
Quick Recap
Best Value
Rank #4
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Rank #3
How should administrators respond?
- Identify the product and version. Check whether the affected system is ESXi, Workstation, Fusion, or Cloud Foundation using the ESXi component, then compare its version with the advisory matrix.
- Use current vendor guidance. Open VMSA-2022-0033 and check the applicable product entry and present support information. The fixed versions above are historical 2022 entries, not a substitute for determining the current supported update for your environment.
- Apply the applicable software update. The advisory directs administrators to apply the patch in its Fixed Version column. Plan and validate the update using your organization’s normal change process.
- If a patch cannot be applied immediately, consult the relevant KB. The advisory lists KB87617 for ESXi and the Cloud Foundation entries, and KB79712 for Fusion 12.x and Workstation 16.x. It identifies these as workaround references rather than detailing the workaround procedure in the advisory itself; follow the applicable vendor article.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

