VMware Security Update – 24 August 2022

VMware has released a security update to address a vulnerability in VMware Tools.

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. The addressed vulnerability could allow the local non-administrative attacker to escalate privileges as a root user in the virtual machine.

The Addressed vulnerability:

VMware Tools Local Privilege Escalation Vulnerability (CVE-2022-31676):

  • CVSS: 7.0
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Privilege Escalation
Vulnerabilities

CVE-2022-31676

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisor

References