CVE-2022-22977: XEE
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22977?
CVE-2022-22977 is a vulnerability in VMware Tools for Windows that allows a malicious user to exploit an XML External Entity (XXE) vulnerability.
What is the severity of CVE-2022-22977?
CVE-2022-22977 has a severity rating of 7.1, which is considered high.
Which software versions are affected by CVE-2022-22977?
VMware Tools for Windows versions 12.0.0, 11.x.y, and 10.x.y are affected by CVE-2022-22977.
How can a malicious actor exploit CVE-2022-22977?
A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit CVE-2022-22977.
How can I mitigate CVE-2022-22977?
To mitigate CVE-2022-22977, it is recommended to upgrade to a fixed version of VMware Tools for Windows.