Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj4f-vfw3-qv39

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

EPSS

Процентиль: 20%
0.00064
Низкий

Дефекты

CWE-269
CWE-367

Связанные уязвимости

CVSS3: 7
nvd
больше 5 лет назад

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

CVSS3: 7
fstec
больше 5 лет назад

Уязвимость системы виртуализации рабочих станций VMware Horizon Client, гипервизоров VMware Remote Console и VMware Fusion, позволяющая нарушителю повысить свои привилегии до уровня root

EPSS

Процентиль: 20%
0.00064
Низкий

Дефекты

CWE-269
CWE-367