Logo
componentopenvmtools
Name
openvmtools
Version
11.3.5-1
Type
library
Description
-
Licenses
LGPL-2.1
PURL
-
CPE
cpe:2.3:a:vmware:tools:11.3.5-18557794:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
11.3.5-18557794

Patches#


#
Title
Author
Resolve
1
Patch #1
Karoly Kasza <kaszak@gmail.com>
2
Patch #2
"Yann E. MORIN" <yann.morin.1998@free.fr>
3
Rename poll.h into vm_poll.h to fix build failure on musl
Fabrice Fontaine <fontaine.fabrice@gmail.com>
4
Remove assumptions about glibc being only libc
Khem Raj <raj.khem@gmail.com>
5
Use configure test for struct timespec
Natanael Copa <ncopa@alpinelinux.org>
6
Fix definition of ALLPERMS and ACCESSPERMS
Natanael Copa <ncopa@alpinelinux.org>
7
Use configure to test for feature instead of platform
Natanael Copa <ncopa@alpinelinux.org>
8
Use configure test for sys/stat.h include
Natanael Copa <ncopa@alpinelinux.org>
9
open-vm-tools/vmhgfs-fuse/fsutils.h: fix build on musl
Fabrice Fontaine <fontaine.fabrice@gmail.com>
10
Make HgfsConvertFromNtTimeNsec aware of 64-bit time_t on i386
Bartosz Brachaczek <b.brachaczek@gmail.com>
11
Properly check authorization on incoming guestOps requests
John Wolfe <jwolfe@vmware.com>
CVE-2022-31676
12
Validate user names and file paths
John Wolfe <john.wolfe@broadcom.com>
CVE-2025-22247
13
glib_stubs: avoid GLib g_free macro redefinition error
Khem Raj <raj.khem@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Patched
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
Exploitable
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
Exploitable
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Patched
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
Exploitable
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.
Exploitable
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.
Exploitable
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.