Vagrant VMWare Utility installation files vulnerable to modification by unprivileged user
Vulnerability Description
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10228
Credits & Attribution
No credits recorded in the NVD database.
More from HashiCorp
View All →Affected Vendor
HashiCorp
View all reports →