Vulnerability Name: | CVE-2012-3569 (CCN-79922) | ||||||||
Assigned: | 2012-11-08 | ||||||||
Published: | 2012-11-08 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-134 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-3569 Source: OSVDB Type: UNKNOWN 87117 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/120101/VMWare-OVF-Tools-Format-String.html Source: CCN Type: SA51240 VMware OVF Tool OVF File Parsing Format String Vulnerability Source: SECUNIA Type: UNKNOWN 51240 Source: MISC Type: UNKNOWN http://technet.microsoft.com/en-us/security/msvr/msvr13-002 Source: CCN Type: OSVDB ID: 87117 VMware OVF Tool OVF File Handling Format String Source: CCN Type: BID-56468 VMware OVF Tool OVF File CVE-2012-3569 Format String Vulnerability Source: CCN Type: VMSA-2012-0015 VMware Hosted Products and OVF Tool address security issues Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2012-0015.html Source: XF Type: UNKNOWN vmware-ovf-format-string(79922) Source: XF Type: UNKNOWN vmware-ovf-format-string(79922) Source: CCN Type: Packet Storm Security [02-06-2013] VMWare OVF Tools Format String Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [02-06-2013] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [02-12-2013] Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-30-2018] VMWare OVF Tools Format String Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |