CVE Vulnerabilities

CVE-2022-31676

Improper Privilege Management

Published: Aug 23, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
ToolsVmware10.0.0 (including)12.1.0 (excluding)
Red Hat Enterprise Linux 7RedHatopen-vm-tools-0:11.0.5-3.el7_9.4*
Red Hat Enterprise Linux 8RedHatopen-vm-tools-0:11.3.5-1.el8_6.1*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatopen-vm-tools-0:10.3.10-3.el8_1.3*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatopen-vm-tools-0:11.0.0-4.el8_2.1*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatopen-vm-tools-0:11.2.0-2.el8_4.1*
Red Hat Enterprise Linux 9RedHatopen-vm-tools-0:11.3.5-1.el9_0.1*
Open-vm-toolsUbuntubionic*
Open-vm-toolsUbuntuesm-infra/bionic*
Open-vm-toolsUbuntuesm-infra/focal*
Open-vm-toolsUbuntuesm-infra/xenial*
Open-vm-toolsUbuntufocal*
Open-vm-toolsUbuntujammy*
Open-vm-toolsUbuntutrusty*
Open-vm-toolsUbuntuupstream*
Open-vm-toolsUbuntuxenial*

Potential Mitigations

References