Vulnerability Name: CVE-2008-1361 (CCN-41257) Assigned: 2008-03-17 Published: 2008-03-17 Updated: 2018-10-11 Summary: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation that causes the authd process to connect to an arbitrary named pipe, a different vulnerability than CVE-2008-1362 . CVSS v3 Severity: 4.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): HighPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C )5.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
4.1 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P )3.0 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-264 Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2008-1361 Source: MLIST Type: UNKNOWN[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues Source: CCN Type: SA29412VMware Server Multiple Vulnerabilities Source: CCN Type: SA29413VMware Products Multiple Vulnerabilities Source: GENTOO Type: UNKNOWNGLSA-201209-25 Source: SREASON Type: UNKNOWN3755 Source: CCN Type: SECTRACK ID: 1019621VMware Windows Hosted Systems Named Pipe Bugs Let Local Users Gain Elevated Privileges Source: SECTRACK Type: UNKNOWN1019621 Source: CCN Type: OSVDB ID: 43898VMware Multiple Products authd Process Named Pipe Manipulation Local Privilege Escalation Source: BUGTRAQ Type: UNKNOWN20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues Source: BID Type: Patch28276 Source: CCN Type: BID-28276VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities Source: CCN Type: VMSA-2008-0005Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line. Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.vmware.com/security/advisories/VMSA-2008-0005.html Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.html Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.vmware.com/support/player/doc/releasenotes_player.html Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.vmware.com/support/player2/doc/releasenotes_player2.html Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.vmware.com/support/server/doc/releasenotes_server.html Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.html Source: CONFIRM Type: UNKNOWNhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.html Source: VUPEN Type: UNKNOWNADV-2008-0905 Source: XF Type: UNKNOWNvmware-authd-privilege-escalation(41257) Source: XF Type: UNKNOWNvmware-authd-privilege-escalation(41257) Vulnerable Configuration: Configuration 1 :cpe:/a:vmware:ace:1.0:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:1.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:1.0.4:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:2.0:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.4:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.5:*:*:*:*:*:*:* OR cpe:/a:vmware:player:2.0:*:*:*:*:*:*:* OR cpe:/a:vmware:player:2.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:player:2.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.0:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.4:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_workstation:5.5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_workstation:6.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_42958:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4_build_44386:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:6.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:vmware:workstation:6.0:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:2.0:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:1.0:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_42958:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4_build_44386:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:6.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:6.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.4:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
vmware ace 1.0
vmware ace 1.0.1
vmware ace 1.0.2
vmware ace 1.0.3
vmware ace 1.0.4
vmware ace 2.0
vmware player 1.0.2
vmware player 1.0.3
vmware player 1.0.4
vmware player 1.0.5
vmware player 2.0
vmware player 2.0.1
vmware player 2.0.2
vmware server 1.0.3
vmware vmware server 1.0.0
vmware vmware server 1.0.1
vmware vmware server 1.0.2
vmware vmware server 1.0.3
vmware vmware server 1.0.4
vmware vmware workstation 5.5.5
vmware vmware workstation 6.0.1
vmware vmware workstation 6.0.2
vmware workstation 5.5
vmware workstation 5.5.3_build_34685
vmware workstation 5.5.3_build_42958
vmware workstation 5.5.4
vmware workstation 5.5.4_build_44386
vmware workstation 6.0
vmware workstation 6.0
vmware ace 2.0
vmware ace 1.0
vmware server 1.0.3
vmware workstation 5.5
vmware workstation 5.5.3_build_34685
vmware workstation 5.5.3_build_42958
vmware workstation 5.5.4
vmware workstation 5.5.4_build_44386
vmware workstation 5.5.5
vmware workstation 6.0.1
vmware workstation 6.0.2
vmware server 1.0.2
vmware server 1.0.4