buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2022-31676
Component Overview
Vulnerability Overview
Name
CVE-2022-31676
Source
NVD (
link
)
Debian (
link
)
Description
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
CWEs
CWE-269
Published Date
Aug 23, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2022/08/23/3
Mailing List
https://lists.debian.org/debian-lts-announce/2022/08/msg00013.html
Mailing List
https://security.gentoo.org/glsa/202210-27
Third Party Advisory
https://security.netapp.com/advisory/ntap-20221017-0003/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5215
Third Party Advisory
https://www.vmware.com/security/advisories/VMSA-2022-0024.html
Release Notes
http://www.openwall.com/lists/oss-security/2022/08/23/3
Mailing List
https://lists.debian.org/debian-lts-announce/2022/08/msg00013.html
Mailing List
https://security.gentoo.org/glsa/202210-27
Third Party Advisory
https://security.netapp.com/advisory/ntap-20221017-0003/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5215
Third Party Advisory
https://www.vmware.com/security/advisories/VMSA-2022-0024.html
Release Notes
Analysis
#
Affected Component
Analysis
openvmtools
Patched
Vulnerability Rating
#
7.8
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
openvmtools
buildroot
master
11.3.5-18557794
Patched
open-vm-tools
yocto
kirkstone
11.3.5
Patched
open-vm-tools
yocto
master
13.0.10
Not Affected
open-vm-tools
yocto
scarthgap
12.3.5
Not Affected
Resolved with patches
#
openvmtools (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Properly check authorization on incoming guestOps requests
John Wolfe <jwolfe@vmware.com>
CVE-2022-31676
openvmtools (buildroot:master)
#
Title
Author
Resolve
1
Properly check authorization on incoming guestOps requests
John Wolfe <jwolfe@vmware.com>
CVE-2022-31676
open-vm-tools (yocto:kirkstone)
#
Title
Author
Resolve
1
Properly check authorization on incoming guestOps requests.
John Wolfe <jwolfe@vmware.com>
CVE-2022-31676