Security scanners may flag Windows Server virtual machines for Intel chipset vulnerabilities, such as CVE-2023-28388, CVE-2024-21814, and CVE-2019-14596.
This typically occurs when scanners detect Intel Chipset Device Software or INF Utility versions in Windows Server virtual machines that are deemed vulnerable on physical hardware.
Because these types of vulnerabilities relate to the physical Intel chipset and associated utility software, remediation typically involves updates outside of the VMware hypervisor itself.
In a virtualized environment, virtual machines use virtualized hardware presented by the ESXi host. Most hardware-level vulnerabilities are addressed through Microcode/BIOS updates provided by your hardware vendor (OEM) for the physical host.
To resolve or validate these findings, we recommend the following steps: