PT-2007-5351 · Emc · Vmware
Callax
·
Publicado
2007-08-03
·
Atualizado
2017-09-29
·
CVE-2007-4155
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC VMware version 6.0.0
Description
The issue is related to an absolute path traversal vulnerability in a certain ActiveX control in vielib.dll. This allows remote attackers to execute arbitrary local programs by providing a full pathname in the first two arguments to the (1) CreateProcess or (2) CreateProcessEx method.
Recommendations
For EMC VMware version 6.0.0, consider restricting access to the CreateProcess and CreateProcessEx methods in the affected ActiveX control until a patch is available. As a temporary workaround, avoid using full pathnames in the first two arguments to these methods to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vmware