Executive brief
A security vulnerability has been identified in the AMD ionic cloud driver used within VMware ESXi virtualization environments. This flaw could allow a user with low-level access to gain higher administrative privileges on the system. If exploited, an attacker could potentially take full control of the host server, leading to unauthorized data access or disruption of virtualized services.
Technical details
A heap-based buffer overflow (CWE-122) exists in the AMD ionic cloud driver for VMware ESXi. The vulnerability is triggered when the driver improperly handles memory allocation on the heap, allowing data to overwrite adjacent memory locations. An attacker with local access and low privileges can exploit this flaw to escalate their permissions to a higher level. Successful exploitation could lead to arbitrary code execution within the context of the ESXi hypervisor. The attack requires local access and carries a high complexity (AC:H) according to the vendor's CVSS assessment.
Affected products
- AMD ionic cloud driver for VMware ESXi
Timeline
- 2026-05-13: advisory: Initial disclosure by AMD and NVD publication.