CVE-2022-31693

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jun 7, 2023
Updated: Jan 7, 2025
CWE ID 404

Summary

CVE-2022-31693 is a denial-of-service vulnerability affecting VMware Tools for Windows versions prior to 12.1.5, 11.x.y, and 10.x.y. A malicious local user in the Windows guest OS can exploit this issue by triggering a PANIC in the VM3DMP driver, resulting in a denial-of-service condition for the Windows guest OS. This vulnerability could potentially disrupt the normal functioning of the virtual machine, posing a risk for organizations using the affected VMware Tools versions. It is recommended that affected organizations update to the latest VMware Tools version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share