Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.809797
Categoría:Privilege escalation
Título:VMware Player Code Execution And Privilege Escalation Vulnerabilities (VMSA-2012-0015) - Windows
Resumen:VMware Player is prone to code execution and privilege escalation vulnerabilities.
Descripción:Summary:
VMware Player is prone to code execution and privilege escalation vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Insecure process threads permissions.

- Format string error in VMware OVF Tool.

- Untrusted search path error.

Vulnerability Impact:
Successful exploitation will allow attackers
to execute arbitrary code or cause denial-of-service conditions and also gain
elevated privileges on the target host.

Affected Software/OS:
VMware Player version 4.x before 4.0.5

Solution:
Upgrade to VMware Player version
4.0.5 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-3569
http://packetstormsecurity.com/files/120101/VMWare-OVF-Tools-Format-String.html
http://technet.microsoft.com/en-us/security/msvr/msvr13-002
http://osvdb.org/87117
http://secunia.com/advisories/51240
XForce ISS Database: vmware-ovf-format-string(79922)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79922
Common Vulnerability Exposure (CVE) ID: CVE-2012-5458
BugTraq ID: 56469
http://www.securityfocus.com/bid/56469
http://osvdb.org/87118
XForce ISS Database: workstation-player-priv-esc(79924)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79924
Common Vulnerability Exposure (CVE) ID: CVE-2012-5459
BugTraq ID: 56470
http://www.securityfocus.com/bid/56470
http://osvdb.org/87119
XForce ISS Database: workstation-dll-code-exec(79923)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79923
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.