yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-22247
Component Overview
Vulnerability Overview
Name
CVE-2025-22247
Source
NVD (
link
)
Debian (
link
)
Description
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
CWEs
CWE-59
Published Date
May 12, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
open-vm-tools
Patched
Vulnerability Ratings
#
6.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
openvmtools
buildroot
2025.02.x
11.3.5-18557794
Patched
openvmtools
buildroot
master
11.3.5-18557794
Patched
open-vm-tools
yocto
kirkstone
11.3.5
Patched
open-vm-tools
yocto
master
13.0.10
Not Affected
Resolved with patches
#
openvmtools (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Validate user names and file paths
John Wolfe <john.wolfe@broadcom.com>
CVE-2025-22247
openvmtools (buildroot:master)
#
Title
Author
Resolve
1
Validate user names and file paths
John Wolfe <john.wolfe@broadcom.com>
CVE-2025-22247
open-vm-tools (yocto:kirkstone)
#
Title
Author
Resolve
1
Validate user names and file paths
John Wolfe <john.wolfe@broadcom.com>
CVE-2025-22247
open-vm-tools (yocto:scarthgap)
#
Title
Author
Resolve
1
Validate user names and file paths
John Wolfe <john.wolfe@broadcom.com>
CVE-2025-22247