VMware Local privilege escalation vulnerability (CVE-2022-31676)

Incident Report for Ekco UK

Resolved

This incident has been resolved.
Posted Jan 08, 2024 - 13:36 GMT

Update

We are continuing to investigate this issue.
Posted Jan 08, 2024 - 13:35 GMT

Investigating

VMware support have advised a local privilege escalation vulnerability that affects our Telehouse West and Slough vCloud platforms. The vulnerability is for VM Tools component which runs on the virtual machines. Updates are available to remediate the vulnerability. More information about the vulnerability can be found here: https://www.vmware.com/security/advisories/VMSA-2022-0024.html If you manage your own guest OS please update VM tools versions to 12.1.0 and 10.3.25 (for older version 10 VM Tools). We will be in touch with all managed customers with list of affected virtual machines and coordinating update schedule
Posted Aug 25, 2022 - 12:45 BST
This incident affected: Cloud (Compute).