Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

open-vm-tools: Local Priviledge Escalation Vulnerability (CVE-2022-31676) #4284

Closed
CamberLoid opened this issue Nov 4, 2022 · 1 comment
Closed
Labels
security Topic/issue involves a security issue/fixed

Comments

@CamberLoid
Copy link
Member

CamberLoid commented Nov 4, 2022

CVE IDs

CVE-2022-31676

Other security advisory IDs

Description

VMware Tools 12.1.0 fixes a local privilege escalation vulnerability, which may allow a malicious actor with local non-administrative access to the Guest OS to escalate privileges as a root user in the virtual machine.

Reference:

Patches

N/A

PoC(s)

N/A

@CamberLoid CamberLoid added the security Topic/issue involves a security issue/fixed label Nov 4, 2022
CamberLoid added a commit that referenced this issue Nov 4, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 10, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 11, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 12, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 23, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 23, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 27, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 27, 2022
* Fix CVE-2022-31676
* Add some TO-DOs at defines file, including some features related to recent
pakreqs.

Signed-off-by: Camber Huang <camber@poi.science>
@CamberLoid
Copy link
Member Author

Fixed via #4290

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed
Projects
None yet
Development

No branches or pull requests

1 participant