Vulnerability Name: | CVE-2012-2450 (CCN-75377) |
Assigned: | 2012-05-03 |
Published: | 2012-05-03 |
Updated: | 2017-12-14 |
Summary: | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS.
|
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Gain Privileges |
References: | Source: MITRE Type: CNA CVE-2012-2450
Source: OSVDB Type: UNKNOWN 81695
Source: CCN Type: SA49019 VMware ESX Server / ESXi Multiple Vulnerabilities
Source: CCN Type: SA49032 VMware Workstation / Player / Fusion Two Privilege Escalation Vulnerabilities
Source: SECUNIA Type: UNKNOWN 49032
Source: CCN Type: SA50093 VMware Workstation / Player Multiple Vulnerabilities
Source: CCN Type: OSVDB ID: 81695 VMware Multiple Product Virtual SCSI Device Out-of-bounds Write Local Privilege Escalation
Source: BID Type: UNKNOWN 53369
Source: CCN Type: BID-53369 VMware Multiple Products Multiple Memory Corruption Privilege Escalation Vulnerabilities
Source: SECTRACK Type: UNKNOWN 1027019
Source: CCN Type: VMSA-2012-0009 VMware Workstation, Player, ESXi and ESX patches address critical security issues
Source: CCN Type: VMSA-2012-0009.2 VMware Workstation, Player, Fusion, ESXi and ESX patches address critical security issues
Source: CONFIRM Type: Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2012-0009.html
Source: XF Type: UNKNOWN esxserver-scsi-priv-esc(75377)
Source: XF Type: UNKNOWN esxserver-scsi-priv-esc(75377)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:16852
|
Vulnerable Configuration: | Configuration 1: cpe:/a:vmware:workstation:8.0:*:*:*:*:*:*:*OR cpe:/a:vmware:workstation:8.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:workstation:8.0.2:*:*:*:*:*:*:* Configuration 2: cpe:/a:vmware:player:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:player:4.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:player:4.0.2:*:*:*:*:*:*:* Configuration 3: cpe:/a:vmware:fusion:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.0.2:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.1:*:*:*:*:*:*:*OR cpe:/a:vmware:fusion:4.1.1:*:*:*:*:*:*:* Configuration 4: cpe:/o:vmware:esxi:3.5:*:*:*:*:*:*:*OR cpe:/o:vmware:esxi:3.5:1:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:*:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:1:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:2:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:3:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.0:4:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.1:*:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.1:1:*:*:*:*:*:*OR cpe:/o:vmware:esxi:4.1:2:*:*:*:*:*:*OR cpe:/o:vmware:esxi:5.0:*:*:*:*:*:*:* Configuration 5: cpe:/o:vmware:esx:3.5:*:*:*:*:*:*:*OR cpe:/o:vmware:esx:3.5:update1:*:*:*:*:*:*OR cpe:/o:vmware:esx:3.5:update2:*:*:*:*:*:*OR cpe:/o:vmware:esx:3.5:update3:*:*:*:*:*:*OR cpe:/o:vmware:esx:4.0:*:*:*:*:*:*:*OR cpe:/o:vmware:esx:4.1:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:vmware:workstation:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:esx_server:3.5:*:*:*:*:*:*:*OR cpe:/a:vmware:esxi:3.5:*:*:*:*:*:*:*OR cpe:/a:vmware:esx_server:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:esxi:4.0:*:*:*:*:*:*:*OR cpe:/a:vmware:workstation:7.0:*:*:*:*:*:*:*OR cpe:/a:vmware:player:3.0:*:*:*:*:*:*:*OR cpe:/a:vmware:esxi:4.1:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |