Vulnerability identifier: #VU60939
Vulnerability risk: Low
CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-426
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
VMware Tools
Client/Desktop applications /
Other client software
Vendor: VMware, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure loading of files. A local privileged user on the guest OS can place a specially crafted library into the current working directory and execute arbitrary code with elevated (SYSTEM) privileges on the guest OS.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
VMware Tools: 10.0.0 - 11.3.5
External links
https://www.vmware.com/security/advisories/VMSA-2022-0007.html
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.