CVE-2022-31693: Medium severity open vm tools vulnerability
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31693?
CVE-2022-31693 is a denial-of-service vulnerability in the VM3DMP driver of VMware Tools for Windows.
What is the severity of CVE-2022-31693?
CVE-2022-31693 has a severity rating of 5.5 (medium).
Which software is affected by CVE-2022-31693?
VMware Tools for Windows versions 12.x.y prior to 12.1.5, 11.x.y, and 10.x.y are affected by CVE-2022-31693.
How can a malicious actor exploit CVE-2022-31693?
A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service.
How can I fix CVE-2022-31693?
To fix CVE-2022-31693, upgrade VMware Tools for Windows to version 12.1.5 or newer.