CVE-2021-21997: Medium severity open vm tools vulnerability
VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest operating system, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest operating system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this VMware Tools for Windows vulnerability?
The vulnerability ID for this VMware Tools for Windows vulnerability is CVE-2021-21997.
What is the severity rating for CVE-2021-21997?
The severity rating for CVE-2021-21997 is medium.
How can a malicious actor exploit CVE-2021-21997?
A malicious actor with local user privileges in the Windows guest operating system, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service.
What is the affected software for CVE-2021-21997?
The affected software for CVE-2021-21997 is VMware Tools for Windows versions prior to 11.3.0.
How can I fix CVE-2021-21997?
To fix CVE-2021-21997, update VMware Tools for Windows to version 11.3.0 or later.