VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs, which might allow Windows guest OS users to gain privileges by placing a Trojan horse program at an unspecified location on the guest OS disk
Published Apr 12, 2010
8.5
HIGHCVSS 2.0
EPSS 1.64%
Description
VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs, which might allow Windows guest OS users to gain privileges by placing a Trojan horse program at an unspecified location on the guest OS disk.
Affected products
No data.
Configuration 1
- 6.5.0
- 6.5.1
- 6.5.2
- 6.5.3
Configuration 2
Configuration 3
Configuration 4
Configuration 5
Configuration 6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html mailing-listx_refsource_BUGTRAQ
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html mailing-listx_refsource_FULLDISC
- http://lists.vmware.com/pipermail/security-announce/2010/000090.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://secunia.com/advisories/39198 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39206 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xml vendor-advisoryx_refsource_GENTOO
- http://www.acrossecurity.com/aspr/ASPR-2010-04-12-2-PUB.txt x_refsource_MISC
- http://www.securityfocus.com/bid/39394 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1023832 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id?1023833 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2010-0007.html x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html | mailing-listx_refsource_BUGTRAQ | |
| http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html | mailing-listx_refsource_FULLDISC | |
| http://lists.vmware.com/pipermail/security-announce/2010/000090.html | mailing-listx_refsource_MLISTPatchVendor Advisory | |
| http://secunia.com/advisories/39198 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/39206 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://security.gentoo.org/glsa/glsa-201209-25.xml | vendor-advisoryx_refsource_GENTOO | |
| http://www.acrossecurity.com/aspr/ASPR-2010-04-12-2-PUB.txt | x_refsource_MISC | |
| http://www.securityfocus.com/bid/39394 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id?1023832 | vdb-entryx_refsource_SECTRACK | |
| http://www.securitytracker.com/id?1023833 | vdb-entryx_refsource_SECTRACK | |
| http://www.vmware.com/security/advisories/VMSA-2010-0007.html | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.