Intel chipset vulnerabilities reported on Windows Server virtual machines
search cancel

Intel chipset vulnerabilities reported on Windows Server virtual machines

book

Article ID: 445914

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Security scanners may flag Windows Server virtual machines for Intel chipset vulnerabilities, such as CVE-2023-28388, CVE-2024-21814, and CVE-2019-14596.

Environment

  • VMware vSphere ESXi
  • Virtual machine running the Windows operating system

Cause

This typically occurs when scanners detect Intel Chipset Device Software or INF Utility versions in Windows Server virtual machines that are deemed vulnerable on physical hardware.

Resolution

Because these types of vulnerabilities relate to the physical Intel chipset and associated utility software, remediation typically involves updates outside of the VMware hypervisor itself.

In a virtualized environment, virtual machines use virtualized hardware presented by the ESXi host. Most hardware-level vulnerabilities are addressed through Microcode/BIOS updates provided by your hardware vendor (OEM) for the physical host.

To resolve or validate these findings, we recommend the following steps:

  1. Physical Host Updates: Ensure your physical ESXi hosts are running the latest BIOS/Firmware/Microcode updates from your hardware vendor, as these often contain the necessary Intel-provided fixes.
  2. Guest OS Drivers: Verify if manual Intel Chipset drivers were installed within the Windows Server 2019 guest. For virtualized environments, we generally recommend using the drivers provided via VMware Tools.
  3. Scanner Validation: If your security scanner identifies these based on software versions within the guest OS, and you have updated the physical host BIOS, the findings may be considered non-exploitable (false positives) as the VM lacks direct access to the physical chipset. It would fall on Microsoft and/or the hardware vendor to validate this.

Additional Information

Broadcom Downloads