CVE-2022-22977

Severity
7.1HIGH
EPSS
0.0%
top 87.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 24
Latest updateMay 25

Description

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a denial-of-service condition or unintended information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5vmware_tools_for_windowsVMware Tools for Windows (12.0.0, 11.x.y and 10.x.y)
NVDvmware/tools12.0.012.0.5+2

🔴Vulnerability Details

2
GHSA
GHSA-325x-vgx6-jr39: VMware Tools for Windows(122022-05-25
CVEList
CVE-2022-22977: VMware Tools for Windows(122022-05-24

📋Vendor Advisories

1
VMware
VMware Tools for Windows update addresses an XML External Entity (XXE) vulnerability (CVE-2022-22977)2022-05-24
CVE-2022-22977 (HIGH CVSS 7.1) | VMware Tools for Windows(12.0.0 | cvebase.io