Open VM Tools could be made to overwrite files as the administrator.. ========================================================================== Ubuntu Security Notice USN-7508-1 May 13, 2025 open-vm-tools vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Open VM Tools could be made to overwrite files as the administrator. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: It was discovered that Open VM Tools incorrectly handled certain file operations. An attacker in a guest could use this issue to perform insecure file operations and possibly elevate privileges in the guest. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 open-vm-tools 2:12.5.0-1ubuntu0.1 Ubuntu 24.10 open-vm-tools 2:12.4.5-1ubuntu0.1 Ubuntu 24.04 LTS open-vm-tools 2:12.4.5-1~ubuntu0.24.04.2 Ubuntu 22.04 LTS open-vm-tools 2:12.3.5-3~ubuntu0.22.04.2 Ubuntu 20.04 LTS open-vm-tools 2:11.3.0-2ubuntu0~ubuntu20.04.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7508-1 CVE-2025-22247 Package Information: https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.5.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.4.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.4.5-1~ubuntu0.24.04.2 https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.3.5-3~ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/open-vm-tools/2:11.3.0-2ubuntu0~ubuntu20.04.8 . Critical vulnerability in Open VM Tools for Ubuntu couldresult in unauthorized file modifications and elevated privileges; prompt action is essential.. Open VM Tools Security, Ubuntu Security Advisory, Privilege Escalation Threat. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Open VM Tools.. ========================================================================== Ubuntu Security Notice USN-6463-2 December 06, 2023 open-vm-tools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Open VM Tools. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: USN-6463-1 fixed vulnerabilities in Open VM Tools. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker with Guest Operations privileges could possibly use this issue to elevate their privileges. (CVE-2023-34058) Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): open-vm-tools 2:11.0.5-4ubuntu0.18.04.3+esm3 open-vm-tools-desktop 2:11.0.5-4ubuntu0.18.04.3+esm3 Ubuntu 16.04 LTS (Available with Ubuntu Pro): open-vm-tools 2:10.2.0-3~ubuntu0.16.04.1+esm4 open-vm-tools-desktop 2:10.2.0-3~ubuntu0.16.04.1+esm4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6463-2 https://ubuntu.com/security/notices/USN-6463-1 CVE-2023-34058, CVE-2023-34059 . Essentialpatches for Open VM Tools address several security flaws in Ubuntu's 16.04 and 18.04 Long Term Support editions.. Open VM Tools, Ubuntu Security Notice, Privilege Escalation Updates. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Open VM Tools.. ========================================================================== Ubuntu Security Notice USN-6463-1 October 31, 2023 open-vm-tools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Open VM Tools. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker Guest Operations privileges could possibly use this issue to escalate privileges. (CVE-2023-34058) Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: open-vm-tools 2:12.3.0-1ubuntu0.1 open-vm-tools-desktop 2:12.3.0-1ubuntu0.1 Ubuntu 23.04: open-vm-tools 2:12.1.5-3ubuntu0.23.04.3 open-vm-tools-desktop 2:12.1.5-3ubuntu0.23.04.3 Ubuntu 22.04 LTS: open-vm-tools 2:12.1.5-3~ubuntu0.22.04.4 open-vm-tools-desktop 2:12.1.5-3~ubuntu0.22.04.4 Ubuntu 20.04 LTS: open-vm-tools 2:11.3.0-2ubuntu0~ubuntu20.04.7 open-vm-tools-desktop 2:11.3.0-2ubuntu0~ubuntu20.04.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6463-1 CVE-2023-34058, CVE-2023-34059 Package Information: https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.3.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.1.5-3ubuntu0.23.04.3 https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.1.5-3~ubuntu0.22.04.4 https://launchpad.net/ubuntu/+source/open-vm-tools/2:11.3.0-2ubuntu0~ubuntu20.04.7 . Security vulnerabilities in Open VM Tools addressed in Ubuntu 23.10, 23.04, 22.04 LTS, and 20.04 LTS through important updates.. Open VM Tools Security, Ubuntu Updates, Critical Security Issues. . Severity: Critical. LinuxSecurity.com Team
Open VM Tools could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-6365-1 September 13, 2023 open-vm-tools vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Open VM Tools could allow unintended access to network services. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker could possibly use this issue to bypass SAML token signature verification and perform VMware Tools Guest Operations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: open-vm-tools 2:12.1.5-3ubuntu0.23.04.2 Ubuntu 22.04 LTS: open-vm-tools 2:12.1.5-3~ubuntu0.22.04.3 Ubuntu 20.04 LTS: open-vm-tools 2:11.3.0-2ubuntu0~ubuntu20.04.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6365-1 CVE-2023-20900 Package Information: https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.1.5-3ubuntu0.23.04.2 https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.1.5-3~ubuntu0.22.04.3 https://launchpad.net/ubuntu/+source/open-vm-tools/2:11.3.0-2ubuntu0~ubuntu20.04.6 . A security flaw in Open VM Tools for Ubuntu may expose network services to unauthorized access. It is advised to perform an update for protection.. Open Tools Access Risk, Ubuntu Guest Operations, Security Update Hand, SAML Token Bypass. . Severity: Critical. LinuxSecurity.com Team
open-vm-tools is a package that provides Open VMware Tools for virtual machines hosted on VMware. It was discovered that Open VM Tools incorrectly handled certain . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3531-1
open-vm-tools could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-5578-1 August 24, 2022 open-vm-tools vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: open-vm-tools could be made to run programs as an administrator. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: It was discovered that Open VM Tools incorrectly handled certain requests. An attacker inside the guest could possibly use this issue to gain root privileges inside the virtual machine. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: open-vm-tools 2:11.3.5-1ubuntu4.1 Ubuntu 20.04 LTS: open-vm-tools 2:11.3.0-2ubuntu0~ubuntu20.04.3 Ubuntu 18.04 LTS: open-vm-tools 2:11.0.5-4ubuntu0.18.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5578-1 CVE-2022-31676 Package Information: https://launchpad.net/ubuntu/+source/open-vm-tools/2:11.3.5-1ubuntu4.1 https://launchpad.net/ubuntu/+source/open-vm-tools/2:11.3.0-2ubuntu0~ubuntu20.04.3 https://launchpad.net/ubuntu/+source/open-vm-tools/2:11.0.5-4ubuntu0.18.04.2 . Understand the risks associated with the Open VM Tools flaw impacting Ubuntu versions and discover the steps necessary to protect your setup by implementing the latest patches.. open-vm-tools, Ubuntu security, administrative access, virtualization security, system updates. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.