CVE-2025-22247: Insecure file handling vulnerability
Published May 12, 2025
·Updated
Insecure file handling vulnerability
Affected Software
3 affected componentsFixes available
VMware open-vm-tools
Microsoft cbl2 open-vm-tools 11.3.0-4
Microsoft azl3 open-vm-tools 12.3.5-2
Event History
May 12, 2025
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Sep 27, 2025
Data Sourced
via Microsoft·01:03 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:03 AM
Affected Software
Updated
via Microsoft·01:03 AM
Affected Software
Updated
via Microsoft·01:03 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-22247?
CVE-2025-22247 is classified as a high severity vulnerability due to its potential impact on file integrity.
2
How do I fix CVE-2025-22247?
To remediate CVE-2025-22247, ensure that VMware Tools is updated to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-22247?
CVE-2025-22247 is an insecure file handling vulnerability within VMware Tools.
4
Who is affected by CVE-2025-22247?
CVE-2025-22247 affects guest VM users of VMware Tools who have non-administrative privileges.
5
What can attackers do with CVE-2025-22247?
Attackers leveraging CVE-2025-22247 can tamper with local files and trigger insecure file operations within the guest VM.