First published: Wed Jun 07 2023(Updated: )
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Tools | >=10.0.0<12.1.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31693 is a denial-of-service vulnerability in the VM3DMP driver of VMware Tools for Windows.
CVE-2022-31693 has a severity rating of 5.5 (medium).
VMware Tools for Windows versions 12.x.y prior to 12.1.5, 11.x.y, and 10.x.y are affected by CVE-2022-31693.
A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service.
To fix CVE-2022-31693, upgrade VMware Tools for Windows to version 12.1.5 or newer.