Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:17509

Опубликовано: 08 окт. 2025
Источник: rocky
Оценка: Important

Описание

Important: open-vm-tools security update

The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines.

Security Fix(es):

  • open-vm-tools: Local privilege escalation in open-vm-tools (CVE-2025-41244)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
open-vm-toolsx86_642.el8_10.1open-vm-tools-12.3.5-2.el8_10.1.x86_64.rpm
open-vm-tools-desktopx86_642.el8_10.1open-vm-tools-desktop-12.3.5-2.el8_10.1.x86_64.rpm
open-vm-tools-salt-minionx86_642.el8_10.1open-vm-tools-salt-minion-12.3.5-2.el8_10.1.x86_64.rpm
open-vm-tools-sdmpx86_642.el8_10.1open-vm-tools-sdmp-12.3.5-2.el8_10.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.8
ubuntu
10 месяцев назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
redhat
10 месяцев назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
nvd
10 месяцев назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
msrc
11 дней назад

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

CVSS3: 7.8
debian
10 месяцев назад

VMware Aria Operations and VMware Tools contain a local privilege esca ...