logo

Critical VMware Tools VGAuth Vulnerabilities Enable Full System Access for Attackers

ID: 02fccf63-298a-5b7c-815e-78f35de9b5ad

STIX ID: report--02fccf63-298a-5b7c-815e-78f35de9b5ad

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-07-25

Date Updated: 2026-04-21

Author: Florence

...
...

Two vulnerabilities in VMware Tools VGAuth (CVE-2025-22230 and CVE-2025-22247) allow local users on Windows virtual machines to achieve SYSTEM-level access through named-pipe hijacking and path traversal combined with symlink/TOCTOU techniques; CVE-2025-22230 was patched in VMware Tools 12.5.1 and CVE-2025-22247 in 12.5.2, and organizations are advised to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.