ZeroHour
Security Affairspublished ()ingested @securityaffairs

VMware fixed a privilege escalation issue in VMware Tools

mediumVulnerabilityimportance 35CVE-2022-31676

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-31676
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability.

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.

NVD description · AI analysis pending
7.8<1%
  • vmware tools
  • vmware debian linux
  • vmware fedora
  • +1 more
Full article170 words · extracted from securityaffairs.com · click to collapse

VMware this week released patches to address an important-severity vulnerability in the VMware Tools suite of utilities.

The virtualization giant VMware this week released patches to address an important-severity flaw, tracked as CVE-2022-31676, which impacts the VMware Tools suite of utilities.

VMware Tools is a set of services and modules that enable several features in company products for better management of, and seamless user interactions with, guests operating systems.

An attacker with local non-administrative access to the Guest OS can trigger the CVE-2022-31676 flaw to escalate privileges on a compromised system.

“VMware Tools was impacted by a local privilege escalation vulnerability.” reads the advisory “A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine,”

The flaw impacts Tools on both Windows and Linux platforms, fixed version released by the company are 12.1.0 and 10.3.25.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, privilege escalation)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/134791/security/vmware-vmware-tools-flaw.html