VulnerabilityModified
CVE-2009-3281
The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.
HIGH 7.2EPSS 0.93%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vmware/fusion
- Source
- cve@mitre.org
References
- http://lists.vmware.com/pipermail/security-announce/2009/000066.htmlVendor Advisory
- http://secunia.com/advisories/36928Vendor Advisory
- http://securitytracker.com/id?1022981
- http://www.vmware.com/security/advisories/VMSA-2009-0013.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2009/2811Vendor Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000066.htmlVendor Advisory
- http://secunia.com/advisories/36928Vendor Advisory
- http://securitytracker.com/id?1022981
- http://www.vmware.com/security/advisories/VMSA-2009-0013.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2009/2811Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.