Vulnerability Name: | CVE-2012-2449 (CCN-75376) |
Assigned: | 2012-05-03 |
Published: | 2012-05-03 |
Updated: | 2017-12-14 |
Summary: | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial of service (out-of-bounds write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS.
|
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-119
|
Vulnerability Consequences: | Gain Privileges |
References: | Source: MITRE Type: CNA CVE-2012-2449
Source: OSVDB Type: UNKNOWN 81694
Source: CCN Type: SA49019 VMware ESX Server / ESXi Multiple Vulnerabilities
Source: CCN Type: SA49032 VMware Workstation / Player / Fusion Two Privilege Escalation Vulnerabilities
Source: SECUNIA Type: UNKNOWN 49032
Source: CCN Type: SA50093 VMware Workstation / Player Multiple Vulnerabilities
Source: CCN Type: OSVDB ID: 81694 VMware Multiple Product Virtual Floppy Device Out-of-bounds Write Local Privilege Escalation
Source: BID Type: UNKNOWN 53369
Source: CCN Type: BID-53369 VMware Multiple Products Multiple Memory Corruption Privilege Escalation Vulnerabilities
Source: SECTRACK Type: UNKNOWN 1027019
Source: CCN Type: VMSA-2012-0009 VMware Workstation, Player, ESXi and ESX patches address critical security issues
Source: CCN Type: VMSA-2012-0009.2 VMware Workstation, Player, Fusion, ESXi and ESX patches address critical security issues
Source: CONFIRM Type: UNKNOWN http://www.vmware.com/security/advisories/VMSA-2012-0009.html
Source: XF Type: UNKNOWN vmware-esxserver-floppy-priv-esc(75376)
Source: XF Type: UNKNOWN vmware-esxserver-floppy-priv-esc(75376)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:16863
|
Vulnerable Configuration: | Configuration 1: cpe:/a:vmware:workstation:8.0:*:*:*:*:*:*:*OR cpe:/a:vmware:workstation:8.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:workstation:8.0.2:*:*:*:*:*:*:* Configuration 2: cpe:/a:vmware:player:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:player:4.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:player:4.0.2:*:*:*:*:*:*:* Configuration 3: cpe:/a:vmware:fusion:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.0.2:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.1:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.1.1:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.1.2:*:*:*:*:*:*:* Configuration 4: cpe:/o:vmware:esxi:3.5:*:*:*:*:*:*:*OR cpe:/o:vmware:esxi:3.5:1:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:*:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:1:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:2:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:3:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:4:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.1:*:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.1:1:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.1:2:*:*:*:*:*:*OR cpe:/o:vmware:esxi:5.0:*:*:*:*:*:*:* Configuration 5: cpe:/o:vmware:esx:3.5:*:*:*:*:*:*:*OR cpe:/o:vmware:esx:3.5:update1:*:*:*:*:*:*OR cpe:/o:vmware:esx:3.5:update2:*:*:*:*:*:*OR cpe:/o:vmware:esx:3.5:update3:*:*:*:*:*:*OR cpe:/o:vmware:esx:4.0:*:*:*:*:*:*:*OR cpe:/o:vmware:esx:4.1:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:vmware:workstation:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:esx_server:3.5:*:*:*:*:*:*:*OR cpe:/a:vmware:esxi:3.5:*:*:*:*:*:*:*OR cpe:/a:vmware:esx_server:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:esxi:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:workstation:7.0:*:*:*:*:*:*:*OR cpe:/a:vmware:player:3.0:*:*:*:*:*:*:*OR cpe:/a:vmware:esxi:4.1:*:*:*:*:*:*:* Denotes that component is vulnerable |
Oval Definitions |
|
BACK |