Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-34046

Опубликовано: 20 окт. 2023
Источник: nvd
CVSS3: 6.7
CVSS3: 7
EPSS Низкий

Описание

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
Версия от 13.0.0 (включая) до 13.5 (исключая)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00108
Низкий

6.7 Medium

CVSS3

7 High

CVSS3

Дефекты

CWE-367
CWE-367

Связанные уязвимости

CVSS3: 6.7
github
больше 2 лет назад

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

CVSS3: 6.7
fstec
больше 2 лет назад

Уязвимость гипервизора VMware Fusion, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 29%
0.00108
Низкий

6.7 Medium

CVSS3

7 High

CVSS3

Дефекты

CWE-367
CWE-367