USN-7508-1: Open VM Tools vulnerability
USN-7508-1: Open VM Tools vulnerability
Publication date: 13 May 2025
Overview :Open VM Tools could be made to overwrite files as the administrator.
Releases
25.04, 24.10, 24.04 LTS, 22.04 LTS, 20.04 LTS
Packages
open-vm-tools - Open VMware Tools for virtual machines hosted on VMware
Details
It was discovered that Open VM Tools incorrectly handled certain file
operations. An attacker in a guest could use this issue to perform insecure
file operations and possibly elevate privileges in the guest.
Update instructions
In general, a standard system update will make all the necessary changes.
- 25.04 plucky open-vm-tools – 2:12.5.0-1ubuntu0.1
- 24.10 oracular open-vm-tools – 2:12.4.5-1ubuntu0.1
- 24.04 noble open-vm-tools – 2:12.4.5-1~ubuntu0.24.04.2
- 22.04 jammy open-vm-tools – 2:12.3.5-3~ubuntu0.22.04.2
- 20.04 focal open-vm-tools – 2:11.3.0-2ubuntu0~ubuntu20.04.8