Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1363

Опубликовано: 20 мар. 2008
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 1.0.5 (исключая)
cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 2.0.1 (исключая)
cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 1.0.6 (исключая)
cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 2.0.3 (исключая)
cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 1.0.5 (исключая)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
Версия от 5.5 (включая) до 5.5.6 (исключая)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
Версия от 6.0 (включая) до 6.0.3 (исключая)

EPSS

Процентиль: 13%
0.00044
Низкий

7.2 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 17 лет назад

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."

debian
больше 17 лет назад

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware P ...

github
больше 3 лет назад

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."

EPSS

Процентиль: 13%
0.00044
Низкий

7.2 High

CVSS2

Дефекты

CWE-264