CVE-2022-22983
VMware Workstation Player vulnerability analysis and mitigation

Overview

VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability identified as CVE-2022-22983. The vulnerability was privately reported to VMware and disclosed on August 9, 2022. VMware has evaluated this issue to be in the Moderate severity range with a CVSS v3.1 base score of 5.9 (NVD CVSS, VMware Advisory).

Technical details

The vulnerability is classified as an insufficiently protected credentials issue (CWE-522). It received a CVSS v3.1 base score of 5.9 (Medium) with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N. This indicates that the vulnerability requires local access, low attack complexity, low privileges, and user interaction, while potentially resulting in high confidentiality impact (NVD CVSS).

Impact

The vulnerability could lead to the disclosure of user passwords of the remote server connected through VMware Workstation. The impact is primarily focused on confidentiality, with no direct impact on integrity or availability of the system (VMware Advisory).

Mitigation and workarounds

VMware has released version 16.2.4 to address this vulnerability. No workarounds are available, and users are advised to apply the security patch as soon as possible. The fix is available for VMware Workstation 16.x running on Windows systems (VMware Advisory).

Additional resources


SourceThis report was generated using AI

Related VMware Workstation Player vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-20872HIGH8.8
  • NixOSNixOS
  • fusion
NoYesApr 25, 2023
CVE-2023-20854HIGH8.4
  • VMware Workstation PlayerVMware Workstation Player
  • cpe:2.3:a:vmware:workstation
NoYesFeb 03, 2023
CVE-2023-20869HIGH8.2
  • NixOSNixOS
  • cpe:2.3:a:vmware:workstation
NoYesApr 25, 2023
CVE-2023-34044MEDIUM6
  • NixOSNixOS
  • fusion
NoYesOct 20, 2023
CVE-2023-20870MEDIUM6
  • NixOSNixOS
  • cpe:2.3:a:vmware:workstation
NoYesApr 25, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management