Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:17429

Опубликовано: 08 окт. 2025
Источник: rocky
Оценка: Important

Описание

Important: open-vm-tools security update

The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines.

Security Fix(es):

  • open-vm-tools: Local privilege escalation in open-vm-tools (CVE-2025-41244)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
open-vm-toolsx86_641.el10_0.1open-vm-tools-12.5.0-1.el10_0.1.x86_64.rpm
open-vm-tools-desktopx86_641.el10_0.1open-vm-tools-desktop-12.5.0-1.el10_0.1.x86_64.rpm
open-vm-tools-salt-minionx86_641.el10_0.1open-vm-tools-salt-minion-12.5.0-1.el10_0.1.x86_64.rpm
open-vm-tools-sdmpx86_641.el10_0.1open-vm-tools-sdmp-12.5.0-1.el10_0.1.x86_64.rpm
open-vm-tools-testx86_641.el10_0.1open-vm-tools-test-12.5.0-1.el10_0.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
nvd
около 1 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
debian
около 1 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege esca ...

suse-cvrf
26 дней назад

Security update for open-vm-tools

suse-cvrf
29 дней назад

Security update for open-vm-tools