CVE-2008-1361
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation that causes the authd process to connect to an arbitrary named pipe, a different vulnerability than CVE-2008-1362.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vmware/ace · vmware/player · vmware/server · vmware/vmware server · vmware/vmware workstation · vmware/workstation
- Source
- cve@mitre.org
References
- http://lists.vmware.com/pipermail/security-announce/2008/000008.html
- http://security.gentoo.org/glsa/glsa-201209-25.xml
- http://securityreason.com/securityalert/3755
- http://securitytracker.com/id?1019621
- http://www.securityfocus.com/archive/1/489739/100/0/threaded
- http://www.securityfocus.com/bid/28276Patch
- http://www.vmware.com/security/advisories/VMSA-2008-0005.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
- http://www.vupen.com/english/advisories/2008/0905/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41257
- http://lists.vmware.com/pipermail/security-announce/2008/000008.html
- http://security.gentoo.org/glsa/glsa-201209-25.xml
- http://securityreason.com/securityalert/3755
- http://securitytracker.com/id?1019621
- http://www.securityfocus.com/archive/1/489739/100/0/threaded
- http://www.securityfocus.com/bid/28276Patch
- http://www.vmware.com/security/advisories/VMSA-2008-0005.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
- http://www.vupen.com/english/advisories/2008/0905/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41257
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.