CVE-2022-31676
Summary
| CVE | CVE-2022-31676 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-23 20:15:00 UTC |
| Updated | 2023-11-07 03:47:00 UTC |
| Description | VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: open-vm-tools-12.1.0-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: open-vm-tools-12.1.0-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| open-vm-tools: Local Privilege Escalation (GLSA 202210-27) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| oss-security - [SECURITY ADVISORY] open-vm-tools: Local privilege escalation
vulnerability (CVE-2022-31676) |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 36 Update: open-vm-tools-12.0.5-3.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: open-vm-tools-12.1.0-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: open-vm-tools-12.0.5-3.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5215-1 open-vm-tools |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 37 Update: open-vm-tools-12.1.0-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3081-1] open-vm-tools security update |
MLIST |
lists.debian.org |
|
| CVE-2022-31676 VMware Tools Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| VMSA-2022-0024 |
MISC |
www.vmware.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160075 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2022-6357)
- 160079 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2022-6358)
- 160080 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2022-6381)
- 180961 Debian Security Update for open-vm-tools (DSA 5215-1)
- 180964 Debian Security Update for open-vm-tools (DLA 3081-1)
- 184492 Debian Security Update for open-vm-tools (CVE-2022-31676)
- 198908 Ubuntu Security Notification for Open VM Tools Vulnerability (USN-5578-1)
- 240650 Red Hat Update for open-vm-tools (RHSA-2022:6358)
- 240651 Red Hat Update for open-vm-tools (RHSA-2022:6356)
- 240652 Red Hat Update for open-vm-tools (RHSA-2022:6355)
- 240653 Red Hat Update for open-vm-tools (RHSA-2022:6357)
- 240654 Red Hat Update for open-vm-tools (RHSA-2022:6381)
- 257194 CentOS Security Update for open-vm-tools (CESA-2022:6381)
- 283095 Fedora Security Update for open (FEDORA-2022-cd23eac6f4)
- 283124 Fedora Security Update for open (FEDORA-2022-1c9c0bacaf)
- 355593 Amazon Linux Security Advisory for open-vm-tools : ALAS2-2023-2114
- 376866 VMware Tools Local Privilege Escalation Vulnerability (VMSA-2022-0024)
- 377054 Alibaba Cloud Linux Security Update for open-vm-tools (ALINUX2-SA-2022:0039)
- 377104 Alibaba Cloud Linux Security Update for open-vm-tools (ALINUX3-SA-2022:0159)
- 502492 Alpine Linux Security Update for open-vm-tools
- 502493 Alpine Linux Security Update for open-vm-tools
- 502494 Alpine Linux Security Update for open-vm-tools
- 6140210 AWS Bottlerocket Security Update for open-vm-tools (GHSA-62q8-gpwh-r68x)
- 710657 Gentoo Linux open-vm-tools Local Privilege Escalation Vulnerability (GLSA 202210-27)
- 752518 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2022:2935-1)
- 752519 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2022:2936-1)
- 752527 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2022:2961-1)
- 752531 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2022:2985-1)
- 752537 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2022:2986-1)
- 940656 AlmaLinux Security Update for open-vm-tools (ALSA-2022:6357)
- 940658 AlmaLinux Security Update for open-vm-tools (ALSA-2022:6358)
- 960382 Rocky Linux Security Update for open-vm-tools (RLSA-2022:6357)
- 960483 Rocky Linux Security Update for open-vm-tools (RLSA-2022:6358)