VMware has released a patch to address a critical authentication bypass vulnerability, identified as CVE-2025-22230, affecting its Windows Tools suite versions 11.x.x and 12.x.x. This flaw, which has a CVSS score of 7.8, allows unauthorized access, posing a high risk to users. The patch is included in VMware Tools version 12.5.1, which users are urged to install immediately, as no workaround is available. Additionally, CrushFTP versions 10 and 11 have been found to contain a separate unauthenticated HTTP(S) access vulnerability, although it is not currently being actively exploited. Security experts recommend updating both VMware Tools and CrushFTP to mitigate these risks.
CVE-2024-55963: Appsmith’s Default PostgreSQL Misconfiguration Leads to RCE, PoC Releases https://t.co/dm2D8DXCrl
CISA Flags Active Exploits in Sitecore CMS: CVE-2019-9874 and CVE-2019-9875, PoC Publishes https://t.co/Fc6jNfYspM
CVE-2025-30232: Use-After-Free Vulnerability in Exim Exposes Systems to Privilege Escalation https://t.co/hWSDODNmn1