Lucene search

K
mageiaGentoo FoundationMGASA-2022-0342
HistorySep 21, 2022 - 9:15 p.m.

Updated open-vm-tools packages fix security vulnerability

2022-09-2121:15:27
Gentoo Foundation
advisories.mageia.org
36
open-vm-tools
security vulnerability
privilege escalation
virtual machine
cve-2022-31676
unix

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine (CVE-2022-31676).

OSVersionArchitecturePackageVersionFilename
Mageia8noarchopen-vm-tools< 11.2.5-1.1open-vm-tools-11.2.5-1.1.mga8

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%