Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801912
Categoría:Privilege escalation
Título:VMware Workstation 'vmrun' Library Path Privilege Escalation Vulnerability (VMSA-2011-0006) - Linux
Resumen:VMware Workstation is prone to a local privilege escalation; vulnerability.
Descripción:Summary:
VMware Workstation is prone to a local privilege escalation
vulnerability.

Vulnerability Insight:
The flaw is caused by an error in the 'vmrun' utility when
handling library paths, which could be exploited to execute arbitrary code by tricking a user into
running a vulnerable utility in a directory containing a specially crafted file.

Vulnerability Impact:
Successful exploitation will allow attacker to execute arbitrary
code with elevated privileges, which may aid in other attacks.

Affected Software/OS:
VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536.

Solution:
Apply the patch or update to Workstation 7.1.4 build 385536.

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1126
BugTraq ID: 47094
http://www.securityfocus.com/bid/47094
Bugtraq: 20110330 VMSA-2011-0006 VMware vmrun utility local privilege escalation (Google Search)
http://www.securityfocus.com/archive/1/517240/100/0/threaded
http://lists.vmware.com/pipermail/security-announce/2011/000131.html
http://securitytracker.com/id?1025270
http://secunia.com/advisories/43885
http://secunia.com/advisories/43943
http://securityreason.com/securityalert/8173
http://www.vupen.com/english/advisories/2011/0816
XForce ISS Database: vmware-vmrun-privilege-escalation(66472)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66472
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.