Input validation error in VMware Tools - CVE-2025-22247

 

Input validation error in VMware Tools - CVE-2025-22247

Published: May 12, 2025


Vulnerability identifier: #VU108928
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22247
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass certain security restrictions.

The vulnerability exists due to insecure file handling. A local user can tamper with local files to trigger insecure file operations within that VM.


Affected software

VMware Tools
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
Desktop Applications Module
Containers Module
Basesystem Module
openSUSE Leap
Ubuntu
Fedora
open-vm-tools
open-vm-tools (Ubuntu package)
open-vm-tools (Debian package)
open-vm-tools-sdmp
open-vm-tools-desktop
open-vm-tools
open-vm-tools-desktop-debuginfo
open-vm-tools-salt-minion
open-vm-tools-debuginfo
open-vm-tools-sdmp-debuginfo
libvmtools0
libvmtools0-debuginfo
open-vm-tools-debugsource
open-vm-tools-containerinfo
libvmtools-devel
open-vm-tools-containerinfo-debuginfo

How to mitigate CVE-2025-22247

Install updates from vendor's website.

VMware Tools - update to 12.5.2
open-vm-tools (Ubuntu package) - addressed in versions 2:10.2.0-3~ubuntu0.16.04.1+esm5, 2:11.0.5-4ubuntu0.18.04.3+esm4, 2:11.3.0-2ubuntu0~ubuntu20.04.8, 2:12.3.5-3~ubuntu0.22.04.2, 2:12.4.5-1ubuntu0.1, 2:12.4.5-1~ubuntu0.24.04.2, 2:12.5.0-1ubuntu0.1
open-vm-tools (Debian package) - update to 2:12.2.0-1+deb12u3
open-vm-tools-sdmp - update to 12.3.5-2
open-vm-tools-desktop - update to 12.3.5-2
open-vm-tools - update to 12.3.5-2
open-vm-tools - addressed in versions 12.5.2-1.fc41, 12.5.2-1.fc42
open-vm-tools-desktop-debuginfo - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-salt-minion - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-sdmp - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-desktop - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-debuginfo - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-sdmp-debuginfo - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
libvmtools0 - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
libvmtools0-debuginfo - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-debugsource - addressed in versions 12.5.2-4.83.1, 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-containerinfo - addressed in versions 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
libvmtools-devel - addressed in versions 12.5.2-150300.58.1, 12.5.2-150600.3.12.1
open-vm-tools-containerinfo-debuginfo - addressed in versions 12.5.2-150300.58.1, 12.5.2-150600.3.12.1

External References

Related Security Bulletins