VYPR

open-vm-tools

by Open VM Tools

CVEs (3)

  • CVE-2023-34059HigOct 27, 2023
    risk 0.48cvss 7.4epss 0.00

    open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

  • CVE-2009-1143HigNov 23, 2022
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

  • CVE-2009-1142MedNov 23, 2022
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.