PT-2004-3407 · Vmware · Vmware Workstation

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2515

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware Workstation version 4.5.2 build-8848
Description A format string issue might allow local users to execute arbitrary code via format string specifiers in command line arguments, but only if running with elevated privileges. It is unclear if default or typical circumstances would allow VMware to run with such elevated privileges.
Recommendations For version 4.5.2 build-8848, consider running VMware Workstation with restricted privileges to minimize the risk of exploitation. As a temporary workaround, avoid using format string specifiers in command line arguments until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2515

Affected Products

Vmware Workstation