{"id":"AZL-67797","summary":"CVE-2025-22247 affecting package open-vm-tools for versions less than 11.3.0-4","details":"VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.","modified":"2026-04-21T04:38:15.919546Z","published":"2025-05-12T11:15:49Z","upstream":["CVE-2025-22247"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22247"}],"affected":[{"package":{"name":"open-vm-tools","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/open-vm-tools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.3.0-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-67797.json"}}],"schema_version":"1.7.5"}