CVE-2024-10228
Vagrant VMWare Utility installation files vulnerable to modification by unprivileged user
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.8EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Oct 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Affected products
HashiCorp · VagrantWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →