Vulnerability Description
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a denial-of-service condition or unintended information disclosure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Tools | >= 10.0.0, <= 10.3.24 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.vmware.com/security/advisories/VMSA-2022-0015.htmlVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2022-0015.htmlVendor Advisory
FAQ
What is CVE-2022-22977?
CVE-2022-22977 is a vulnerability with a CVSS score of 7.1 (HIGH). VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where ...
How severe is CVE-2022-22977?
CVE-2022-22977 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22977?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Tools, Microsoft Windows.