VMware Tools 12.0 kurulu Guest OS larda non-admnistrative erişimi olan kötü niyetli bir kişi-mekanizma bu açığı kullanarak VM’de bir root user hakkına sahip olabiliyor.

 

  1. Impacted Products
  • VMware Tools

 

Advisory ID:  VMSA-2022-0024

CVSSv3 Range:  7.0

Issue Date:  2022-08-23

Updated On:  2022-08-23 (Initial Advisory)

CVE(s):  CVE-2022-31676

Synopsis:  VMware Tools update addresses a local privilege escalation vulnerability (CVE-2022-31676)

Product Version Running On CVE Identifier CVSSv3 Severity Fixed Version Workarounds Additional Documentation
VMware Tools 12.x.y, 11.x.y Windows CVE-2022-31676 7.0 important 12.1.0 None None
VMware Tools 12.x.y, 11.x.y Linux CVE-2022-31676 7.0 important 12.1.0 None None
VMware Tools 10.x.y Linux CVE-2022-31676 7.0 important 10.3.25 None None