CVE-2009-1143
Publication date 23 November 2022
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| open-vm-tools | ||
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal | Ignored | |
| 18.04 LTS bionic | Ignored | |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Ignored |
Notes
mdeslaur
mount.vmhgfs not suid root in Debian and Ubuntu, negligible security impact. Upstream commit removes vmhgfs in favour of hgfs-fuse. Since this has no security impact on Ubuntu, and there is no upstream fix for the issue, we will not be fixing this in stable releases.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | High |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | High |
| Availability impact | High |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |