ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-VVF Administrator
          • vcp-vvf-2.
        • Close
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • VVF 9 and VCF 9
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • XCP-NG
    • XCP-NG
    • Close
  • Proxmox
    • Proxmox
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Windows Server 2025
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • Privacy policy
    • PDFs and Books
    • Close
  • Free

Vulnerability in your VMs – VMware Tools Update

By Vladan SEGET | Last Updated: May 19, 2025

Shares

Recent news about vulnerabilities siting quietly inside our VMware VMs is rather worrying. What if, attacker was going to hack our infrastructure from inside of our VMs? And what if not only Windows VMs, but also Linux VMs were affected? VMware Tools Update is important as your ESXi patch update. This vulnerability is labeled as CVE-2025-22247. I'm back to report on this my friends. I took a couple of days off, being on other projects other than IT or virtualization, but now I'm slowly getting back to my keyboard -:). So, let's talk about vulnerabilities!

As being said, the latest vulnerability is present in VMware tools, but the open-source implementation, open-vm-tools, is also affected. As you know, open-vm-tools are the native Linux alternative to VMware tools for Linux. We have blogged about it a very very long time ago. As such, the recent vulnerability is also affecting your VMs that are using open-vm-tools.

There is now known vulnerability discovered by Sergey Bliznyuk from Positive Technologies and this vulnerability allows attackers with non-admin rights on Guest VM to tamper the local files to trigger insecure file operations within that VM.

The latest update from VMware/Broadcom

Description:
VMware Tools contains an insecure file handling vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.1.

Known Attack Vectors:
A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

Resolution:
To remediate CVE-2025-22247 apply the patches listed in the ‘Fixed Version' column of the ‘Response Matrix' found below.

Workarounds:
None

Additional Documentation:
None

Acknowledgements:
VMware would like to thank Sergey Bliznyuk of Positive Technologies for reporting this issue to us.

Where to get the fixes from?

You can go to this page at Broadcom.com website here. There are all the informations you need.

Fixed Version(s) and Release Notes:

VMware Tools 12.5.2

Downloads and Documentation:

Final Words

The fixed VMware Tools version is labeled 12.5.2. Broadcom said that Linux vendors will distribute the updates for users, and fixed versions may differ depending on the Linux distribution version and the distribution vendor.

As you can see, the regular check on the latest vulnerabilities is a must. More and more often, the vulnerabilities are discovered and solutions are provided. However, hacker never sleeps so they also uses zero day vulnerabilities for which there aren't any patches, because they were not reported. However, the vast majority of hacks happens because IT managers do not patch their infrastructure often enough and if they do, they do not patch everything. Please make sure that your VMware tools are up-to-date!

 

More posts from ESX Virtualization:

  • VMware ESXi FREE is FREE again!
  • No more FREE licenses of VMware vSphere for vExperts – What’s your options?
  • Two New VMware Certified Professional Certifications for VMware administrators: VCP-VVF and VCP-VCF
  • Patching ESXi Without Reboot – ESXi Live Patch – Yes, since ESXi 8.0 U3
  • Update ESXi Host to the latest ESXi 8.0U3b without vCenter
  • Upgrade your VMware VCSA to the latest VCSA 8 U3b – latest security patches and bug fixes
  • VMware vSphere 8.0 U2 Released – ESXi 8.0 U2 and VCSA 8.0 U2 How to update
  • What’s the purpose of those 17 virtual hard disks within VMware vCenter Server Appliance (VCSA) 8.0?
  • VMware vSphere 8 Update 2 New Upgrade Process for vCenter Server details
  • VMware vSAN 8 Update 2 with many enhancements announced during VMware Explore
  • What’s New in VMware Virtual Hardware v21 and vSphere 8 Update 2?
  • Homelab v 8.0 
    • NXJ6412 Maxtang EHL30 TPM Alert in vCenter Server 8.0 BIOS Config
    • vSphere 8 Lab with Cohesity and VMware vExpert gift – Maxtang’s NX 6412 NUC
    • VMware Cohesity vExpert Gift VMware EXPLORE 2022 Barcelona
  • vSphere 8.0 Page
  • ESXi 7.x to 8.x upgrade scenarios
  • VMware vCenter Server 7.03 U3g – Download and patch
  • Upgrade VMware ESXi to 7.0 U3 via command line
  • VMware vCenter Server 7.0 U3e released – another maintenance release fixing vSphere with Tanzu
  • What is The Difference between VMware vSphere, ESXi and vCenter

Stay tuned through RSS, and social media channels (Twitter, FB, YouTube)

5/5 - (1 vote)
Shares

| Filed Under: Cloud, Featured, Free Stuff Tagged With: VMware Tools update Leave a Comment

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x17, Veeam Vanguard x11, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Private Sponsors

 

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
Click to Become a Sponsor

Most Recent

  • Shadow Wearables in Enterprise Environments: The Hidden Risks of Connected Devices
  • Windows 11 26H1 Latest Build – Technical Deep Dive into OS Build 28000.1575
  • This Virtualization Platform from NexaVM will blow your mind
  • XorMon NG 2.1.0 – Enhanced Full-Stack Monitoring with New Backup, DB, and Storage Support
  • Ufficio Zero Linux: Boosting Productivity with an Italian Open-Source Desktop Built for Real Work – and Learn Italian!
  • LAB: Xen Orchestra 6 and XCP-NG – installation from the source via script from Roni Väyrynen
  • StarWind VTL: Boosting Immutability and Ransomware Protection in Your Own Datacenter
  • Why still become vExpert in 2026?
  • Windows Server 2025 latest updates and Native NVMe Support
  • This is it – Most Popular Blog posts in 2025

Get new posts by email:

 

 

 

 

Deals

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Friendly Websites and Blogs

  • vBlog.io
  • VMware Engineer Jobs
 

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2026 ·Dynamik-Gen · Genesis Framework · Hosted with HostColor.com