Vulnerability Name: | CVE-2012-5459 (CCN-79923) | ||||||||
Assigned: | 2012-11-08 | ||||||||
Published: | 2012-11-08 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." Per: http://cwe.mitre.org/data/definitions/426.html "CWE-426: Untrusted Search Path" | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.9 High (CVSS v2 Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-5459 Source: OSVDB Type: UNKNOWN 87119 Source: CCN Type: SA51237 VMware Workstation / Player Multiple Vulnerabilities Source: CCN Type: OSVDB ID: 87119 VMware Multiple Product Path Subversion Arbitrary DLL Injection Code Execution Source: BID Type: UNKNOWN 56470 Source: CCN Type: BID-56470 VMware Player and Workstation Insecure Library Loading Arbitrary Code Execution Vulnerability Source: CCN Type: VMSA-2012-0015 VMware Hosted Products and OVF Tool address security issues Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2012-0015.html Source: XF Type: UNKNOWN workstation-dll-code-exec(79923) Source: XF Type: UNKNOWN workstation-dll-code-exec(79923) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |