CVE-2021-21999
23.06.2021, 12:15
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | app_volumes | 2.0 ≤ 𝑥 < 2.18.10 |
vmware | app_volumes | 4 ≤ 𝑥 < 2103 |
vmware | remote_console | 12.0.0 ≤ 𝑥 < 12.0.1 |
vmware | tools | 11.0.0 ≤ 𝑥 < 11.2.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration