Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 473 respecto a la semana anterior
Críticas / altas1434▲ 199 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Modificada | Alta (7) | 0.40% | — | Vmware Open VM ToolsDebian Linux | 27/10/2023 | 17/6/2026 | open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs. | |
| Modificada | Alta (7.5) | 0.67% | — | Vmware Open VM ToolsDebian LinuxVmware ToolsFedoraproject Fedora | 27/10/2023 | 17/6/2026 | VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that… | |
| Modificada | Alta (7.5) | 1.5% | — | Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+1 | 31/8/2023 | 17/6/2026 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest… | |
| Modificada | Alta (7) | 0.26% | — | Vmware Open-vm-tools | 23/11/2022 | 16/6/2026 | An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter). | |
| Modificada | Media (6.7) | 0.28% | — | Vmware Open VM Tools | 23/11/2022 | 16/6/2026 | An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled. | |
| Modificada | Baja (3.3) | 0.44% | — | Vmware Open-vm-tools | 10/4/2011 | 16/6/2026 | vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a… |