CVE-2024-10228 Information

Description

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user introducing potential for unauthorized file system writes. This vulnerability CVE-2024-10228 was fixed in Vagrant VMWare Utility 1.0.23

Reference

https://discuss.hashicorp.com/t/hcsec-2024-25-vagrant-vmware-utility-installation-files-vulnerable-to-modification-by-unprivileged-user

Share on: