All errata/c9f2/ALT-PU-2024-1233-4
ALT-PU-2024-1233-4

Package update open-vm-tools in branch c9f2

Version12.3.5-alt0.c9.1
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (12)

BDU:2023-00152
LOW3.3

Уязвимость драйвера VM3DMP набора утилит VMware Tools операционных систем Windows, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2023-01-16Modified: 2024-02-27
CVSS 3.xLOW 3.3
CVSS:3.x/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.0LOW 1.7
CVSS:2.0/AV:L/AC:L/Au:S/C:N/I:N/A:P
BDU:2023-03162
LOW3.9

Уязвимость модуля vgauth компонента VMware Tools гипервизора VMware ESXi, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

Published: 2023-06-15Modified: 2024-11-11
CVSS 3.xLOW 3.9
CVSS:3.x/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
CVSS 2.0LOW 2.3
CVSS:2.0/AV:L/AC:H/Au:M/C:P/I:P/A:N
BDU:2023-05064
HIGH7.5

Уязвимость набора утилит VMware Tools, связанная с возможностью обхода подписи SAML-токена, позволяющая нарушителю повысить свои привилегии

Published: 2023-09-04Modified: 2024-11-11
CVSS 3.xHIGH 7.5
CVSS:3.x/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:A/AC:H/Au:N/C:C/I:C/A:C
BDU:2023-07233
HIGH7.8

Уязвимость набора утилит VMware Tools для операционных систем MacOS, связанная с ошибками при управлении привилегиями, позволяющая нарушителю повысить свои привилегии

Published: 2023-10-28Modified: 2024-02-27
CVSS 3.xHIGH 7.8
CVSS:3.x/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:L/AC:L/Au:S/C:C/I:C/A:C
BDU:2023-07234
HIGH7.5

Уязвимость набора утилит VMware Tools для операционных систем Windows, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии

Published: 2023-10-28Modified: 2025-05-05
CVSS 3.xHIGH 7.5
CVSS:3.x/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.5
CVSS:2.0/AV:A/AC:H/Au:S/C:C/I:C/A:C
BDU:2024-02571
HIGH7.0

Уязвимость набора утилит VMware Tools, связанная с некорректным присваиванием привилегий, позволяющая нарушителю обойти существующие ограничения безопасности

Published: 2024-04-04Modified: 2025-05-05
CVSS 3.xHIGH 7.0
CVSS:3.x/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.0
CVSS:2.0/AV:L/AC:H/Au:S/C:C/I:C/A:C
References
CVE-2022-31693
MEDIUM5.5

VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS.

Published: 2023-06-07Modified: 2025-01-07
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2023-20867
LOW3.9

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

Published: 2023-06-13Modified: 2025-10-28
CVSS 3.xLOW 3.9
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
References
CVE-2023-20900
HIGH7.5

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

Published: 2023-08-31Modified: 2024-11-21
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-34058
HIGH7.5

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

Published: 2023-10-27Modified: 2025-03-06
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-34059
HIGH7.0

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

Published: 2023-10-27Modified: 2025-03-06
CVSS 3.xHIGH 7.0
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
References

Closed bugs (1)