Vulnerability Name:

CVE-2012-5458 (CCN-79924)

Assigned:2012-11-08
Published:2012-11-08
Updated:2017-08-29
Summary:VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:8.3 High (CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C)
6.2 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2012-5458

Source: OSVDB
Type: UNKNOWN
87118

Source: CCN
Type: SA51237
VMware Workstation / Player Multiple Vulnerabilities

Source: CCN
Type: OSVDB ID: 87118
VMware Multiple Product Process Thread Insecure Permission Local Privilege Escalation

Source: BID
Type: UNKNOWN
56469

Source: CCN
Type: BID-56469
VMware Player and Workstation CVE-2012-5458 Local Privilege Escalation Vulnerability

Source: CCN
Type: VMSA-2012-0015
VMware Hosted Products and OVF Tool address security issues

Source: CONFIRM
Type: Vendor Advisory
http://www.vmware.com/security/advisories/VMSA-2012-0015.html

Source: XF
Type: UNKNOWN
workstation-player-priv-esc(79924)

Source: XF
Type: UNKNOWN
workstation-player-priv-esc(79924)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:player:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:player:4.0.0.18997:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:player:4.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:player:4.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:player:4.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:player:4.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0.0.18997:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0.1.27038:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0.4:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:vmware:player:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:8.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware player 4.0
    vmware player 4.0.0.18997
    vmware player 4.0.1
    vmware player 4.0.2
    vmware player 4.0.3
    vmware player 4.0.4
    vmware workstation 8.0
    vmware workstation 8.0.0.18997
    vmware workstation 8.0.1
    vmware workstation 8.0.1.27038
    vmware workstation 8.0.2
    vmware workstation 8.0.3
    vmware workstation 8.0.4
    microsoft windows *
    vmware player 4.0
    vmware workstation 8.0