VMware has investigated CVE-2021-22040 and CVE-2021-22041 and determined that the possibility of exploitation can be mitigated by performing the steps detailed in the Resolution section of this article.
Please note, that this workaround is meant to be a temporary solution, until the updates documented in VMSA-2022-0004 can be deployed.
Please refer to VMware ESXi Updates For VMSA-2022-0004 and VMSA-2022-0004:VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities for more details about the issue, as well as information regarding which fixed product versions are available.
As a temporary workaround you can remove all USB controllers from your virtual machines, until you are able to mitigate the issue by patching to a fixed product version.
Please be aware that this workaround should only be used as an exception, for it will make multiple features unavailable, such as:
The procedures for removing the virtual USB controller for the specific affected products can be found in the following documents: