PT-2007-5351 · Emc · Vmware

Callax

·

Published

2007-08-03

·

Updated

2017-09-29

·

CVE-2007-4155

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC VMware version 6.0.0
Description The issue is related to an absolute path traversal vulnerability in a certain ActiveX control in vielib.dll. This allows remote attackers to execute arbitrary local programs by providing a full pathname in the first two arguments to the (1) CreateProcess or (2) CreateProcessEx method.
Recommendations For EMC VMware version 6.0.0, consider restricting access to the CreateProcess and CreateProcessEx methods in the affected ActiveX control until a patch is available. As a temporary workaround, avoid using full pathnames in the first two arguments to these methods to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4155

Affected Products

Vmware