[Forgot Password]
Login  Register Subscribe

24003

 
 

131425

 
 

104705

 
 

909

 
 

84119

 
 

133

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2007-5671Date: (C)2008-06-05   (M)2018-02-19


HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : CVSS Score : 4.4
Exploit Score: Exploit Score: 3.4
Impact Score: Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: LOCAL
Attack Complexity: Access Complexity: MEDIUM
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: PARTIAL
Scope: Integrity: PARTIAL
Confidentiality: Availability: PARTIAL
Integrity:  
Availability:  
  
Reference:
SECTRACK-1020197
http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=712
http://www.securityfocus.com/archive/1/archive/1/493148/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/493172/100/0/threaded
SECUNIA-30556
SREASON-3922
ADV-2008-1744
GLSA-201209-25
http://www.vmware.com/security/advisories/VMSA-2008-0009.html

CPE    10
cpe:/a:vmware:esx_server:3.0.2
cpe:/a:vmware:esx_server:2.5.4
cpe:/a:vmware:player:1.0.4
cpe:/a:vmware:server:1.0.3
...
CWE    1
CWE-20

© 2013 SecPod Technologies