Wind River Support Network

HomeDefectsLIN1021-4203
Fixed

LIN1021-4203 : Security Advisory - open-vm-tools - CVE-2022-31676

Created: Aug 25, 2022    Updated: Mar 19, 2025
Resolved Date: Dec 17, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.15
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.

CREATE(Triage):(User=admin) CVE-2022-31676 (https://nvd.nist.gov/vuln/detail/CVE-2022-31676)

CVEs


Live chat
Online