Vulnerability Name: | CVE-2012-1515 (CCN-74480) | ||||||||||||||||
Assigned: | 2012-03-29 | ||||||||||||||||
Published: | 2012-03-29 | ||||||||||||||||
Updated: | 2018-10-12 | ||||||||||||||||
Summary: | VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine. | ||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 8.3 High (CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C) 6.2 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-1515 Source: CCN Type: Packetstorm Security Website VMware High-Bandwidth Backdoor ROM Overwrite Privilege Elevation Source: CCN Type: SA48669 VMware ESX Server / ESXi I/O Handling ROM Overwrite Privilege Escalation Vulnerability Source: CCN Type: SA49454 Microsoft Windows Kernel Two Privilege Escalation Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS12-042 Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2711167) Source: BID Type: UNKNOWN 52820 Source: CCN Type: BID-52820 Microsoft Windows and VMware ESXi/ESX CVE-2012-1515 Local Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1026875 Source: CERT Type: US Government Resource TA12-164A Source: CCN Type: VMSA-2012-0006 VMware ESXi and ESX address several security issues Source: CONFIRM Type: Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2012-0006.html Source: MS Type: UNKNOWN MS12-042 Source: XF Type: UNKNOWN vmware-esxserver-io-privilege-escalation(74480) Source: XF Type: UNKNOWN vmware-esxserver-io-privilege-escalation(74480) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:15209 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:17110 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |