Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-67797.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-67797
Upstream
Published
2025-05-12T11:15:49Z
Modified
2026-04-21T04:38:15.919546Z
Summary
CVE-2025-22247 affecting package open-vm-tools for versions less than 11.3.0-4
Details

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

References

Affected packages

Azure Linux:2 / open-vm-tools

Package

Name
open-vm-tools
Purl
pkg:rpm/azure-linux/open-vm-tools

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.3.0-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-67797.json"