CVE-2022-22943
Published on: Not Yet Published
Last Modified on: 03/17/2022 07:03:00 PM UTC
Certain versions of Tools from Vmware contain the following vulnerability:
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.
- CVE-2022-22943 has been assigned by
secu[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.7 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
VMSA-2022-0007 | www.vmware.com text/html |
![]() |
Related QID Numbers
- 376442 VMware Tools Denial of Service (DoS) Vulnerability (VMSA-2022-0007)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Vmware | Tools | All | All | All | All |
- cpe:2.3:a:vmware:tools:*:*:*:*:windows:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Windows向け「VMware Tools」に脆弱性 - アップデートが公開:Security NEXT security-next.com/134543 “検索パスの設定に問題がある脆弱性「CVE-2022-22943」が明ら… twitter.com/i/web/status/1… | 2022-03-02 12:06:50 |
![]() |
CVE-2022-22943 : VMware Tools for #Windows 11.x.y and 10.x.y prior to 12.0.0 contains an uncontrolled search path… twitter.com/i/web/status/1… | 2022-03-03 22:06:42 |
![]() |
CVE-2022-22943 | 2022-03-03 22:38:44 |