Denial-of-Service Vulnerability in VMware Tools for Windows by VMware
CVE-2021-21997

5.5MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
18 June 2021

Summary

VMware Tools for Windows contains a vulnerability in the VM3DMP driver that allows a malicious local user to exploit the driver, leading to a denial-of-service condition in the guest operating system. This issue can cause the VM3DMP driver to trigger a crash, resulting in loss of service and requiring a restart of the affected virtual machine. Users are advised to update their VMware Tools to the latest version to mitigate this risk.

Affected Version(s)

VMware Tools for Windows VMware Tools for Windows (11.x.y prior to 11.3.0)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.