[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-3650Date: (C)2015-07-16   (M)2023-12-22


vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1032822
SECTRACK-1032823
http://www.vmware.com/security/advisories/VMSA-2015-0005.html
https://www.nettitude.co.uk/vmware-multiple-products-privilege-escalation/

CPE    11
cpe:/a:vmware:player:5.0
cpe:/a:vmware:player:5.0.1
cpe:/a:vmware:workstation:11.1
cpe:/a:vmware:workstation:11.0
...
CWE    1
CWE-284
OVAL    1
oval:org.secpod.oval:def:36450

© SecPod Technologies