[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-5671Date: (C)2008-06-05   (M)2023-12-22


HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \.hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1020197
http://www.securityfocus.com/archive/1/493080/100/0/threaded
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=712
http://www.securityfocus.com/archive/1/493148/100/0/threaded
http://www.securityfocus.com/archive/1/493172/100/0/threaded
SECUNIA-30556
SREASON-3922
ADV-2008-1744
GLSA-201209-25
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
oval:org.mitre.oval:def:5358
oval:org.mitre.oval:def:5688

CPE    10
cpe:/a:vmware:player:1.0.4
cpe:/a:vmware:server:1.0.3
cpe:/a:vmware:workstation:5.5.1
cpe:/a:vmware:workstation:5.5.3
...
CWE    1
CWE-20

© SecPod Technologies