CVE-2022-31693
published 2023-06-07CVE-2022-31693: VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 10web | photo_gallery | <= 1.5.68 | — |
| vmware | tools | >= 10.0.0 < 12.1.5 | 12.1.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Tools for Windows update addresses a denial-of-service vulnerability (CVE-2022-31693)
vendor_vmware·2022-11-29·CVSS 5.5
CVE-2022-31693 [MEDIUM] VMware Tools for Windows update addresses a denial-of-service vulnerability (CVE-2022-31693)
VMSA-2022-0029: VMware Tools for Windows update addresses a denial-of-service vulnerability (CVE-2022-31693)
VMware Tools for Windows contains a denial-of-service vulnerability in the VM3DMP driver. VMware has evaluated the severity of this issue to be in the Low Severity Range with a maximum CVSSv3 base score of 3.3.
CVEs: CVE-2022-31693
Affected products: VMware Tools
GHSA
GHSA-7c26-765q-28xr: VMware Tools for Windows (12
ghsa_unreviewed·2023-06-07
CVE-2022-31693 [MEDIUM] CWE-404 GHSA-7c26-765q-28xr: VMware Tools for Windows (12
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20221223-0009/https://security.netapp.com/advisory/ntap-20230824-0009/https://www.vmware.com/security/advisories/VMSA-2022-0029.htmlhttps://security.netapp.com/advisory/ntap-20221223-0009/https://security.netapp.com/advisory/ntap-20230824-0009/https://www.vmware.com/security/advisories/VMSA-2022-0029.html
2023-06-07
Published