The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
2024-10-29T22:15:03.220
2024-11-07T17:12:45.750
Analyzed
CVSSv3.1: 3.8 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hashicorp | vagrant_vmware_utility | < 1.0.23 | Yes |