Process

ubiquitoussigned

vgauthservice.exe

Broadcom IncFirst seen 2026-06-08

File identity

File details
File type
PE32+ executable
Magic
PE32+ executable (console)
Original name
VGAuthService.exe
Internal name
VGAuthService
Product
VMware Guest Authentication
Signing information
Status
Signed
Publisher
Broadcom Inc
Signer
Broadcom Inc
Issuer
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Signature rate
100%
File version1
  • 12.5.0.6303100%
File size1
  • 159.40 KB100%

Execution context

File paths1
  • C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe100%
User context0

Not observed.

Integrity level0

Not observed.

Instances1
  • 1100%
Session1
  • Session 0100%
Token privileges16
  • SeTcbPrivilege100%
  • SeCreateGlobalPrivilege100%
  • SeCreatePermanentPrivilege100%
  • SeIncreaseBasePriorityPrivilege100%
  • SeAuditPrivilege100%

Ancestry

Parents0

Not observed.

Children0

Not observed.

Grandparents0

Not observed.

Grandchildren0

Not observed.

Behavior

Loaded modules0

Not observed.

Named pipes0

Not observed.

Process handles0

Not observed.

Command-line patterns0

Not observed.

Indicators

Hashes

Not observed.

Analysis

About this process

No analyst write-up yet.

Security notes

No analyst write-up yet.

Anomaly signals

None defined yet.

Telemetry

OS prevalence1
  • Microsoft Windows 11 Enterprise Evaluation100%
Observation timeline
First seen
2026-06-08
Last seen
2026-06-08
Machines
1

Subsearch

Hasbeen seen inof vgauthservice.exe?