PT-2022-2232 · Vmware+1 · Vmware Tools+1
Jens Lewandowski
+1
·
Published
2022-03-01
·
Updated
2022-09-13
·
CVE-2022-22943
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Tools for Windows versions 10.x.y through 11.x.y prior to 12.0.0
Description
The issue is related to an uncontrolled search path vulnerability in VMware Tools for Windows. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.
Recommendations
For versions 10.x.y through 11.x.y prior to 12.0.0, update to version 12.0.0 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Fix
Untrusted Search Path
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Vmware Tools