{"id":"AZL-67806","summary":"CVE-2025-22247 affecting package open-vm-tools for versions less than 12.3.5-2","details":"VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.","modified":"2026-09-14T05:26:59Z","published":"2025-05-12T11:15:49Z","upstream":["CVE-2025-22247"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22247"}],"affected":[{"package":{"name":"open-vm-tools","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/open-vm-tools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3.5-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-67806.json"}}],"schema_version":"1.9.0"}