VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 10 | RedHat | open-vm-tools-0:12.5.0-1.el10_0.1 | * |
Red Hat Enterprise Linux 8 | RedHat | open-vm-tools-0:12.3.5-2.el8_10.1 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | open-vm-tools-0:11.2.0-2.el8_4.5 | * |
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | open-vm-tools-0:11.2.0-2.el8_4.5 | * |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | open-vm-tools-0:11.3.5-1.el8_6.6 | * |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | open-vm-tools-0:11.3.5-1.el8_6.6 | * |
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | open-vm-tools-0:11.3.5-1.el8_6.6 | * |
Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | open-vm-tools-0:12.1.5-2.el8_8.5 | * |
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | open-vm-tools-0:12.1.5-2.el8_8.5 | * |
Red Hat Enterprise Linux 9 | RedHat | open-vm-tools-0:12.5.0-1.el9_6.2 | * |
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | open-vm-tools-0:11.3.5-1.el9_0.6 | * |
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | open-vm-tools-0:12.1.5-1.el9_2.5 | * |
Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | open-vm-tools-0:12.3.5-2.el9_4.1 | * |
Open-vm-tools | Ubuntu | devel | * |
Open-vm-tools | Ubuntu | esm-infra/focal | * |
Open-vm-tools | Ubuntu | jammy | * |
Open-vm-tools | Ubuntu | noble | * |
Open-vm-tools | Ubuntu | plucky | * |
Open-vm-tools | Ubuntu | upstream | * |