First published: Tue Aug 23 2022(Updated: )
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Tools | >=10.0.0<12.1.0 | |
Microsoft Windows | ||
VMware Tools | >=10.0.0<10.3.25 | |
VMware Tools | >=11.0.0<12.1.0 | |
Linux Linux kernel | ||
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
NetApp ONTAP Select Deploy administration utility | ||
debian/open-vm-tools | <=2:10.3.10-1+deb10u2 | 2:10.3.10-1+deb10u5 2:11.2.5-2+deb11u2 2:12.2.0-1+deb12u1 2:12.3.0-1 |
debian/open-vm-tools | <=2:10.3.10-1+deb10u2<=2:12.0.5-2<=2:10.3.10-1<=2:11.2.5-2 | 2:12.1.0-1 2:11.2.5-2+deb11u1 |
IBM BM Security Guardium | <=11.3 | |
IBM Security Guardium | <=11.4 | |
IBM Security Guardium | <=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31676 is a local privilege escalation vulnerability in VMware Tools.
CVE-2022-31676 allows a local authenticated attacker to gain elevated privileges on the system.
CVE-2022-31676 has a severity rating of 7.8 (high).
VMware Tools versions 12.0.0, 11.x.y, and 10.x.y are affected by CVE-2022-31676.
An attacker can exploit CVE-2022-31676 by sending a specially-crafted request to gain elevated privileges as the root user in the virtual machine.