CVE-2022-22977: VMware Tools
High severity, CVSS 7.1. EPSS: 0.8% chance of exploitation in the next 30 days.
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Affected products
- VMware Tools: from 10.0.0, up to and including 10.3.24; from 11.0.0, up to and including 11.3.5; from 12.0.0, before 12.0.5 (fixed in 12.0.5)
Published 2022-05-24. Last modified 2026-06-17.