CVE-2022-22942
HIGHvmwgfx Driver File Descriptor Handling Priv Esc
Title source: metasploitDescription
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.
Exploits (1)
metasploit
WORKING POC
GOOD
by h00die, Mathias Krause · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/vmwgfx_fd_priv_esc.rb
Scores
CVSS v3
7.8
EPSS
0.1353
EPSS Percentile
94.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (2)
vmware/photon_os
3.0
vmware/photon_os
4.0
Published
Dec 13, 2023
Tracked Since
Feb 18, 2026