PT-2022-2232 · Vmware+1 · Vmware Tools+1

Jens Lewandowski

+1

·

Published

2022-03-01

·

Updated

2022-09-13

·

CVE-2022-22943

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware Tools for Windows versions 10.x.y through 11.x.y prior to 12.0.0
Description The issue is related to an uncontrolled search path vulnerability in VMware Tools for Windows. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.
Recommendations For versions 10.x.y through 11.x.y prior to 12.0.0, update to version 12.0.0 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1438
ALT-PU-2022-2579
ALT-PU-2022-2597
BDU:2022-02316
CVE-2022-22943

Affected Products

Alt Linux
Vmware Tools