Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22247

Опубликовано: 12 мая 2025
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

A vulnerability was found in open-vm-tools. A malicious actor with non-administrative privileges on a guest virtual machine (VM) may tamper with the local files to trigger insecure file operations within that VM.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10open-vm-toolsFix deferred
Red Hat Enterprise Linux 7open-vm-toolsOut of support scope
Red Hat Enterprise Linux 8open-vm-toolsFix deferred
Red Hat Enterprise Linux 9open-vm-toolsFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2364261open-vm-tools: Insecure file handling

EPSS

Процентиль: 16%
0.00052
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
6 месяцев назад

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

CVSS3: 6.1
nvd
6 месяцев назад

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

CVSS3: 6.1
msrc
около 2 месяцев назад

Insecure file handling vulnerability

CVSS3: 6.1
debian
6 месяцев назад

VMware Tools contains an insecure file handling vulnerability.A malici ...

suse-cvrf
6 месяцев назад

Security update for open-vm-tools

EPSS

Процентиль: 16%
0.00052
Низкий

6.1 Medium

CVSS3