First published: Wed Oct 25 2023(Updated: )
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Open Vm Tools | >=11.0.0<=12.3.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
ubuntu/open-vm-tools | <2:11.0.5-4ubuntu0.18.04.3+ | 2:11.0.5-4ubuntu0.18.04.3+ |
ubuntu/open-vm-tools | <2:11.3.0-2ubuntu0~ubuntu20.04.7 | 2:11.3.0-2ubuntu0~ubuntu20.04.7 |
ubuntu/open-vm-tools | <2:12.1.5-3~ubuntu0.22.04.4 | 2:12.1.5-3~ubuntu0.22.04.4 |
ubuntu/open-vm-tools | <2:12.1.5-3ubuntu0.23.04.3 | 2:12.1.5-3ubuntu0.23.04.3 |
ubuntu/open-vm-tools | <2:12.3.0-1ubuntu0.1 | 2:12.3.0-1ubuntu0.1 |
ubuntu/open-vm-tools | <2:10.2.0-3~ubuntu0.16.04.1+ | 2:10.2.0-3~ubuntu0.16.04.1+ |
redhat/open-vm-tools | <11.0.0 | 11.0.0 |
IBM Security Guardium | <=11.3 | |
IBM Security Guardium | <=11.4 | |
IBM Security Guardium | <=11.5 | |
IBM Security Guardium | <=12.0 | |
debian/open-vm-tools | 2:11.2.5-2+deb11u3 2:12.2.0-1+deb12u2 2:12.4.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.