CVE-2025-22247
published 2025-05-12CVE-2025-22247: VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to…
PriorityP429medium6.1CVSS 3.1
AVLACLPRLUINSUCLIHAN
EPSS
0.25%
15.9th percentile
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | open-vm-tools | < open-vm-tools 2:12.2.0-1+deb12u3 (bookworm) | open-vm-tools 2:12.2.0-1+deb12u3 (bookworm) |
| msrc | azl3_open-vm-tools_12.3.5-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_open-vm-tools_11.3.0-4_on_cbl_mariner_2.0 | — | — |
| vmware | open-vm-tools | >= 0 < 2:11.2.5-2+deb11u4 | 2:11.2.5-2+deb11u4 |
| vmware | open-vm-tools | >= 0 < 2:12.2.0-1+deb12u3 | 2:12.2.0-1+deb12u3 |
| vmware | open-vm-tools | >= 0 < 2:12.5.0-2 | 2:12.5.0-2 |
| vmware | open-vm-tools | >= 0 < 2:12.5.0-2 | 2:12.5.0-2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open VM Tools vulnerability
vendor_ubuntu·2025-06-03
CVE-2025-22247 Open VM Tools vulnerability
Title: Open VM Tools vulnerability
Summary: Open VM Tools could be made to overwrite files as the administrator.
USN-7508-1 fixed a vulnerability in Open VM Tools. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS
Original advisory details:
It was discovered that Open VM Tools incorrectly handled certain
file operations. An attacker in a guest could use this issue to
perform insecure file operations and possibly elevate privileges
in the guest.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Insecure file handling vulnerability
vendor_msrc·2025-05-13·CVSS 6.1
CVE-2025-22247 [MEDIUM] CWE-59 Insecure file handling vulnerability
Insecure file handling vulnerability
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
vmware: vmware
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en
Ubuntu
Open VM Tools vulnerability
vendor_ubuntu·2025-05-13
CVE-2025-22247 Open VM Tools vulnerability
Title: Open VM Tools vulnerability
Summary: Open VM Tools could be made to overwrite files as the administrator.
It was discovered that Open VM Tools incorrectly handled certain file
operations. An attacker in a guest could use this issue to perform insecure
file operations and possibly elevate privileges in the guest.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
open-vm-tools: Insecure file handling
vendor_redhat·2025-05-12·CVSS 6.1
CVE-2025-22247 [MEDIUM] CWE-266 open-vm-tools: Insecure file handling
open-vm-tools: Insecure file handling
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
A vulnerability was found in open-vm-tools. A malicious actor with non-administrative privileges on a guest virtual machine (VM) may tamper with the local files to trigger insecure file operations within that VM.
Mitigation: Currently, no mitigation is available for this vulnerability.
Package: open-vm-tools (Red Hat Enterprise Linux 10) - Fix deferred
Package: open-vm-tools (Red Hat Enterprise Linux 7) - Out of support scope
Package: rhcos (Red Hat OpenShift Container Platform 4) - Fix deferred
Debian
CVE-2025-22247: open-vm-tools - VMware Tools contains an insecure file handling vulnerability. A malicious actor...
vendor_debian·2025·CVSS 6.1
CVE-2025-22247 [MEDIUM] CVE-2025-22247: open-vm-tools - VMware Tools contains an insecure file handling vulnerability. A malicious actor...
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
Scope: local
bookworm: resolved (fixed in 2:12.2.0-1+deb12u3)
bullseye: resolved (fixed in 2:11.2.5-2+deb11u4)
forky: resolved (fixed in 2:12.5.0-2)
sid: resolved (fixed in 2:12.5.0-2)
trixie: resolved (fixed in 2:12.5.0-2)
OSV
CVE-2025-22247: VMware Tools contains an insecure file handling vulnerability
osv·2025-05-12·CVSS 6.1
CVE-2025-22247 [MEDIUM] CVE-2025-22247: VMware Tools contains an insecure file handling vulnerability
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
GHSA
GHSA-mqmq-2p8r-q32f: VMware Tools contains an insecure file handling vulnerability
ghsa_unreviewed·2025-05-12
CVE-2025-22247 [MEDIUM] CWE-59 GHSA-mqmq-2p8r-q32f: VMware Tools contains an insecure file handling vulnerability
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25683http://www.openwall.com/lists/oss-security/2025/05/12/2http://www.openwall.com/lists/oss-security/2025/05/13/2http://www.openwall.com/lists/oss-security/2025/09/24/3http://www.openwall.com/lists/oss-security/2025/09/25/3http://www.openwall.com/lists/oss-security/2025/09/25/5http://www.openwall.com/lists/oss-security/2025/09/26/1https://lists.debian.org/debian-lts-announce/2025/05/msg00017.html
2025-05-12
Published