← Back

CVE-2022-31676

nvd nist
Published: Aug 23, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.

Affected (8)

Products: Vmware: Tools · Debian: Debian Linux · Fedoraproject: Fedora · +1 more
Show all products
1 product
Tools
1 product
Debian Linux
1 product
Fedora
1 product
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 10.0.0 to 12.1.0
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Vmware
From 10.0.0 to 10.3.25
From 11.0.0 to 12.1.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 36
Version 37
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (18)

Source: security@vmware.com
Mailing ListPatchRelease NotesThird Party Advisory
Source: security@vmware.com
Mailing ListThird Party Advisory
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.