CVE-2021-21999

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
23/06/2021
Last modified:
12/07/2022

Description

VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:* 2.0 (including) 2.18.10 (excluding)
cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:* 4 (including) 2103 (excluding)
cpe:2.3:a:vmware:remote_console:*:*:*:*:*:windows:*:* 12.0.0 (including) 12.0.1 (excluding)
cpe:2.3:a:vmware:tools:*:*:*:*:*:windows:*:* 11.0.0 (including) 11.2.6 (excluding)