PT-2012-3322 · Vmware · Vmware Esxi
Published
2012-05-04
·
Updated
2019-09-27
·
CVE-2012-1516
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware ESXi versions 3.5 through 4.1
VMware ESX versions 3.5 through 4.1
Description
The issue is related to the VMX process in VMware products, which does not properly handle RPC commands. This can be exploited by guest OS users to cause a denial of service, resulting in memory overwrite and process crash, or possibly execute arbitrary code on the host OS. The exploitation involves vectors related to data pointers.
Recommendations
For VMware ESXi versions 3.5 through 4.1, update to a version that properly handles RPC commands to prevent exploitation.
For VMware ESX versions 3.5 through 4.1, update to a version that properly handles RPC commands to prevent exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Esxi