Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j79m-7c8r-83mc

Опубликовано: 17 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

EPSS

Процентиль: 48%
0.00249
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

CVSS3: 7.1
fstec
почти 4 года назад

Уязвимость службы VMX платформы виртуализации VMware Cloud Foundation и гипервизора VMware ESXi, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 48%
0.00249
Низкий

Дефекты

CWE-863