VMware Tools Insecure File Handling Vulnerability

Vulnerability

An insecure file handling vulnerability has been identified in VMware Tools. This vulnerability allows a malicious actor with non-administrative privileges on a guest virtual machine (VM) to manipulate local files, thereby triggering insecure file operations within the VM. The vulnerability is present in open-vm-tools, which is the version of VMware Tools distributed with many Linux distributions.

Impact

Exploitation of this vulnerability could lead to unauthorized file manipulation and potentially allow for other malicious actions within the guest VM.

Remediation

Users can apply the patch available in the VMware Tools 12.5.2 release. For Debian 11, the vulnerability has been fixed in version 2:11.2.5-2+deb11u4.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
2.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.