PT-2004-3407 · Vmware · Vmware Workstation

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2515

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware Workstation version 4.5.2 build-8848
Description A format string issue might allow local users to execute arbitrary code via format string specifiers in command line arguments, but only if running with elevated privileges. It is unclear if default or typical circumstances would allow VMware to run with such elevated privileges.
Recommendations For version 4.5.2 build-8848, consider running VMware Workstation with restricted privileges to minimize the risk of exploitation. As a temporary workaround, avoid using format string specifiers in command line arguments until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2515

Produtos afetados

Vmware Workstation