CVE-2021-21999
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.
Affected (4)
Products: Vmware: App Volumes, Remote Console, Tools
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0 to 2.18.10 | |
| From 12.0.0 to 12.0.1 | |
| From 11.0.0 to 11.2.6 |
References (4)
Source: security@vmware.com
PatchVendor Advisory
Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.