VMware Tools is a set of services and modules that enable several features in VMware products for better management of guests operating systems and seamless user interactions with them. VMware Tools has the ability to pass messages from the host operating system to the guest operating system.
Therefore, VMware Tools is a suite of utilities that enhances the performance of the virtual machine guest operating system and improves the management of the virtual machine. Without VMware Tools installed in your guest operating system, guest performance lacks important functionality. Installing VMware Tools improves these issues low video resolution, inadequate color depth, incorrect display of network speed, restricted movement of the mouse, inability to copy and paste and drag and drop files, missing sound, and provides the ability to take quiesced snapshots of the guest OS, and synchronises the time in the guest operating system with the time on the host
Impacted Product
VMware Tools for Windows
A denial-of-service vulnerability in VMware Tools for Windows was privately reported to VMware. Updates are available to remediate this vulnerability in affected VMware products.
Issue description
VMware Tools for Windows contains a denial-of-service vulnerability in the VM3DMP driver. VMware has evaluated the severity of this issue to be in the Low Severity Range with a maximum CVSSv3 base score of 3.3.
How can this vulnerability be exploited?
On devices where the VMware Tools is installed, an attacker (a malicious actor) with local user privileges in the Windows guest OS can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition in the Windows guest OS.
How can this vulnerability be exploited?
This vulnerability does not have a workaround. To remediate this issue (CVE-2022-31693), please apply the patches listed in the ‘Fixed Version’ column of the ‘Response Matrix’ found below.
Product | Version | Running On | CVE Identifier | CVSSv3 | Severity | Fixed Version | Workarounds | Additional Documentation |
VMware Tools for Windows | 12.x.y, 11.x.y and 10.x.y | Windows | CVE-2022-31693 | 3.3 | Low |
| None
|
Here is the link to the original blogpost.