PT-2008-5120 · Vmware · Hcmon.Sys+4
G
·
Published
2008-08-21
·
Updated
2017-09-29
·
CVE-2008-3761
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 6.5.1 and earlier
VMware Player versions 2.5.1 and earlier
VMware ACE versions 2.5.1 and earlier
VMware Server versions prior to 1.0.9 build 156507
VMware Server versions 2.0.x prior to 2.0.1 build 156745
Description
The issue allows local users to cause a denial of service via a crafted IOCTL request, due to the use of the METHOD NEITHER communication method for IOCTLs in the hcmon.sys driver.
Recommendations
For VMware Workstation versions 6.5.1 and earlier, update to a version later than 6.5.1.
For VMware Player versions 2.5.1 and earlier, update to a version later than 2.5.1.
For VMware ACE versions 2.5.1 and earlier, update to a version later than 2.5.1.
For VMware Server versions prior to 1.0.9 build 156507, update to version 1.0.9 build 156507 or later.
For VMware Server versions 2.0.x prior to 2.0.1 build 156745, update to version 2.0.1 build 156745 or later.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Ace
Vmware Player
Vmware Server
Vmware Workstation
Hcmon.Sys