VMware Tools for Windows update addresses vSockets information-disclosure vulnerability (CVE-2025-41239)
VMware released security advisory VMSA-2025-0013 with Medium severity affecting VMware Tools.
The fix is available in VMware Tools v12.5.3 for Windows available in the VSS-Windows Content Library as Item VMware-Tools-for-Windows-12.5.3.24819442 (see Windows section below) and Linux via open-vm-tools package or patch (see Linux section below).
How-To Remediate
Windows
ITS Private Cloud CLI
Mount the VMware Tools ISO
VMware-Tools-for-Windows-12.5.3.24819442with thevss-cli:vss-cli compute vm set <id> cd up --backing VMware-Tools-for-Windows-12.5.3.24819442 1Proceed with the installation in the OS.
ITS Private Cloud Portal
Login to the
https://cloud-portal.eis.utoronto.caLook for your VM and click on the
Editbutton.Mount the VMWare Tools ISO
VMware-Tools-for-Windows-12.5.3.24819442Proceed with the installation in the OS.
University of Toronto - Since 1827