Known vulnerabilities in open-vm-tools (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:open-vm-tools_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 2
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting open-vm-tools (Red Hat package) open-vm-tools (Red Hat package) is affected by 7 known vulnerabilities: 2 high, 2 medium, 3 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116185 - Improper Access Control
CVE-2025-41244
CWE-284 High
No
Exploited
11.2.0-2.el8_4.5, 11.3.5-1.el8_6.6, 11.3.5-1.el9_0.6, 12.1.5-1.el9_2.5, 12.1.5-2.el8_8.5, 12.3.5-2.el8_10.1, 12.3.5-2.el9_4.1, 12.5.0-1.el9_6.2, 12.5.0-1.el10_0.1 30.09.2025 SB2025093024
SB2025093025
SB2025093036
and 21 more
#VU82560 - Improper Access Control
CVE-2023-34059
CWE-284 Low
No
No
11.0.5-3.el7_9.9, 11.3.5-1.el9_0.5, 12.1.5-1.el9_2.4, 12.1.5-2.el8_8.4, 12.2.5-3.el8_9.1, 12.2.5-3.el9_3.2 30.10.2023 SB2023103026
SB2023103031
SB2023103032
and 32 more
#VU82520 - Improper Authorization
CVE-2023-34058
CWE-285 Medium
No
No
11.0.5-3.el7_9.9, 11.3.5-1.el9_0.5, 12.1.5-1.el9_2.4, 12.1.5-2.el8_8.4, 12.2.5-3.el8_9.1, 12.2.5-3.el9_3.2 27.10.2023 SB2023102702
SB2023103031
SB2023103032
and 33 more
#VU80188 - Cryptographic Issues
CVE-2023-20900
CWE-310 Medium
No
No
10.3.10-3.el8_1.4, 11.0.0-4.el8_2.3, 11.0.5-3.el7_9.7, 11.2.0-2.el8_4.3, 11.3.5-1.el8_6.4, 11.3.5-1.el9_0.4, 12.1.5-1.el9_2.3, 12.1.5-2.el8_8.3 31.08.2023 SB2023083119
SB2023083154
SB2023083155
and 38 more
#VU77208 - Improper Authentication
CVE-2023-20867
CWE-287 High
No
Exploited
11.0.0-4.el8_2.2, 11.0.5-3.el7_9.6, 11.2.0-2.el8_4.2, 11.3.5-1.el8_6.2, 11.3.5-1.el9_0.2, 12.1.5-1.el9_2.1, 12.1.5-2.el8_8 13.06.2023 SB2023061339
SB2023061449
SB2023061649
and 34 more
#VU76017 - UNIX Symbolic Link (Symlink) Following
CVE-2014-4199
CWE-61 Low
No
No
9.10.2-4.el7 11.05.2023 SB2015112003
#VU66726 - Permissions, Privileges, and Access Controls
CVE-2022-31676
CWE-264 Low
No
No
10.3.10-3.el8_1.3, 11.0.0-4.el8_2.1, 11.0.5-3.el7_9.4, 11.2.0-2.el8_4.1, 11.3.5-1.el8_6.1, 11.3.5-1.el9_0.1 23.08.2022 SB2022082317
SB2022082416
SB2022082423
and 36 more