| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801142 |
| Category: | Privilege escalation |
| Title: | VMware Products Guest Privilege Escalation Vulnerability - Nov09 (Win) |
| Summary: | Check for the version of VMware Products |
| Description: | Overview: The host is installed with VMWare product(s) and is prone to Privilege Escalation vulnerability. Vulnerability Insight: An error occurs while setting the exception code when a '#PF' (page fault) exception arises which can be exploited to gain escalated privileges within VMware guest. Impact: Local attacker can exploit this issue to gain escalated privileges in a guest virtual machine. Impact Level: System Affected Software/OS: VMware ACE version 2.5.x prior to 2.5.3 Build 185404, VMware Server version 2.0.x prior to 2.0.2 Build 203138, VMware Server version 1.0.x prior to 1.0.10 Build 203137, VMware Player version 2.5.x prior to 2.5.3 Build 185404, VMware Workstation version 6.5.x prior to 6.5.3 Build 185404 on Windows. Fix: Upgrade your VMWares according to the below link, http://www.vmware.com/security/advisories/VMSA-2009-0015.html References: http://secunia.com/advisories/37172 http://www.vupen.com/english/advisories/2009/3062 http://securitytracker.com/alerts/2009/Oct/1023082.html http://lists.vmware.com/pipermail/security-announce/2009/000069.html |
| Cross-Ref: |
BugTraq ID: 36841 Common Vulnerability Exposure (CVE) ID: CVE-2009-2267 Bugtraq: 20091027 Invalid #PF Exception Code in VMware can result in Guest Privilege Escalation (Google Search) http://www.securityfocus.com/archive/1/archive/1/507539/100/0/threaded Bugtraq: 20091027 VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues (Google Search) http://www.securityfocus.com/archive/1/archive/1/507523/100/0/threaded http://lists.vmware.com/pipermail/security-announce/2009/000069.html http://www.securityfocus.com/bid/36841 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8473 http://securitytracker.com/id?1023082 http://securitytracker.com/id?1023083 http://secunia.com/advisories/37172 http://www.vupen.com/english/advisories/2009/3062 |
| Copyright | Copyright (C) 2009 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|