PT-2012-3321 · Vmware+1 · Vmware Esxi+1

Publicado

2012-04-02

·

Atualizado

2018-10-12

·

CVE-2012-1515

CVSS v2.0

8.3

Alta

VetorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware ESXi versions 3.5 through 4.1 VMware ESX versions 3.5 through 4.1
Description The issue concerns improper implementation of port-based I/O operations, allowing guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine. Additionally, there is an elevation of privilege issue related to how Windows handles BIOS memory, which could allow an attacker to run arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full administrative rights.
Recommendations For VMware ESXi versions 3.5 through 4.1, consider restricting access to the Virtual DOS Machine to minimize the risk of exploitation. For VMware ESX versions 3.5 through 4.1, consider restricting access to the Virtual DOS Machine to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1515

Produtos afetados

Vmware Esxi
Windows