VMware Security Update – 26 March 2025

VMware has released a security update to fix a vulnerability across VMware Tools for Windows.

The addressed vulnerability could allow the attacker with non-administrative privileges on a Windows guest VM to bypass security restrictions and gain the ability to perform certain high-privilege operations within that VM.

VMware Tools Authentication Bypass Vulnerability (CVE-2025-22230):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities

CVE-2025-22230

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Update

References