USN-6365-1: Open VM Tools vulnerability
It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker could possibly use this issue to bypass SAML token signature verification and perform VMware Tools Guest Operations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
USN-6365-1
What is the title of the vulnerability?
Open VM Tools vulnerability
What is the description of the vulnerability?
Open VM Tools incorrectly handles SAML tokens, allowing a remote attacker to bypass SAML token signature verification and perform VMware Tools Guest Operations.
Which software is affected by this vulnerability?
Open VM Tools version 2:12.1.5-3ubuntu0.23.04.2, version 2:12.1.5-3~ubuntu0.22.04.3, and version 2:11.3.0-2ubuntu0~ubuntu20.04.6 on Ubuntu 23.04, 22.04, and 20.04 respectively.
What is the severity of the vulnerability?
This vulnerability is not assigned a severity rating.
How can I fix this vulnerability?
Update to Open VM Tools version 2:12.1.5-3ubuntu0.23.04.2, 2:12.1.5-3~ubuntu0.22.04.3, or 2:11.3.0-2ubuntu0~ubuntu20.04.6 depending on your Ubuntu version.