PT-2010-2857 · Vmware+1 · Vmware Workstation+6
Published
2010-04-12
·
Updated
2017-09-19
·
CVE-2010-1141
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 6.5.x through 6.5.3
VMware Player versions 2.5.x through 2.5.3
VMware ACE versions 2.5.x through 2.5.3
VMware Server versions 2.x through 2.0.1
VMware Fusion versions 2.x through 2.0.5
VMware ESXi versions 3.5 and 4.0
VMware ESX versions 2.5.5, 3.0.3, 3.5, and 4.0
Description
The issue allows user-assisted remote attackers to execute arbitrary code by tricking a Windows guest OS user into clicking on a file stored on a network share, due to improper library access.
Recommendations
For VMware Workstation versions 6.5.x through 6.5.3, update to version 6.5.4 build 246459 or later.
For VMware Player versions 2.5.x through 2.5.3, update to version 2.5.4 build 246459 or later.
For VMware ACE versions 2.5.x through 2.5.3, update to version 2.5.4 build 246459 or later.
For VMware Server versions 2.x through 2.0.1, update to version 2.0.2 build 203138 or later.
For VMware Fusion versions 2.x through 2.0.5, update to version 2.0.6 build 246742 or later.
For VMware ESXi versions 3.5 and 4.0, and VMware ESX versions 2.5.5, 3.0.3, 3.5, and 4.0, update to a version that properly accesses libraries.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Ace
Vmware Esxi
Vmware Fusion
Vmware Player
Vmware Server
Vmware Workstation
Windows