The vendor explicitly identifies these products or versions as containing the fix.
- open-vm-tools-0:12.5.0-1.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-0:12.5.0-1.el10_0.1.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-0:12.5.0-1.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-debuginfo-0:12.5.0-1.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-debuginfo-0:12.5.0-1.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-debugsource-0:12.5.0-1.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-debugsource-0:12.5.0-1.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-desktop-0:12.5.0-1.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-desktop-0:12.5.0-1.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-desktop-debuginfo-0:12.5.0-1.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-desktop-debuginfo-0:12.5.0-1.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- open-vm-tools-salt-minion-0:12.5.0-1.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- Summary
- A flaw was found in VMWare open-vm-tools. A malicious actor with non-administrative privileges on a guest Virtual Machine (VM) could exploit this vulnerability to gain root privileges on the VM. The issue lies in the service-discovery plugin logic, which can execute attacker-controlled binaries from writable paths such as /tmp. Exploitation requires the open-vm-tools-sdmp package to be installed and guest service discovery to be enabled.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
