PT-2007-5351 · Emc · Vmware
Callax
·
Published
2007-08-03
·
Updated
2017-09-29
·
CVE-2007-4155
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC VMware version 6.0.0
Description
The issue is related to an absolute path traversal vulnerability in a certain ActiveX control in vielib.dll. This allows remote attackers to execute arbitrary local programs by providing a full pathname in the first two arguments to the (1) CreateProcess or (2) CreateProcessEx method.
Recommendations
For EMC VMware version 6.0.0, consider restricting access to the CreateProcess and CreateProcessEx methods in the affected ActiveX control until a patch is available. As a temporary workaround, avoid using full pathnames in the first two arguments to these methods to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware