Description
VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.
References (1)
Core 1
Core References
Scores
CVSS v3
7.6
EPSS
0.0003
EPSS Percentile
9.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-863
Status
published
Products (3)
VMware/Tools
11.x.x
VMware/Tools
12.x.x - 12.5.4
VMware/Tools
13.x.x.x - 13.0.5.0
Published
Sep 29, 2025
Tracked Since
Feb 18, 2026