CVE-2008-2100
Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- vmware/ace · vmware/esx server · vmware/esxi · vmware/fusion · vmware/player · vmware/server · vmware/workstation · vmware/esx
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30556Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://securityreason.com/securityalert/3922Third Party Advisory
- http://securitytracker.com/id?1020200Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/493080/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29552Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2008/1744Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42872Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5081Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5647Third Party Advisory
- http://secunia.com/advisories/30556Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://securityreason.com/securityalert/3922Third Party Advisory
- http://securitytracker.com/id?1020200Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/493080/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29552Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2008/1744Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42872Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5081Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5647Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.