VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.
References
Configurations
No configuration.
History
29 Sep 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-29 16:15
Updated : 2025-09-29 19:34
NVD link : CVE-2025-41246
Mitre link : CVE-2025-41246
CVE.ORG link : CVE-2025-41246
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
