VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Details
- CVSS 3.0 Base Score: 6.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade open-vm-tools | Jul 30, 2024 | Jul 28, 2017 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 6, 2021 |
| Suse | — | Upgrade open-vm-tools-desktopUpgrade libvmtools-develUpgrade libvmtools0Upgrade open-vm-toolsUpgrade open-vm-tools-sdmp | Feb 10, 2017 | Feb 10, 2017 |
| Ubuntu | — | Upgrade open-vm-tools | Nov 19, 2024 | Jul 28, 2017 |
| Vmware Vmware Tools | — | Update VMware Tools to the latest version | Jun 3, 2025 | Jul 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub