VulnerabilityModified
CVE-2009-3732
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
HIGH 10.0EPSS 16.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 16.20% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-134
- Affected
- vmware/ace · vmware/player · vmware/server · vmware/workstation
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlBroken Link
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlBroken Link
- http://lists.vmware.com/pipermail/security-announce/2010/000090.htmlMailing List, Patch, Vendor Advisory
- http://secunia.com/advisories/39110Not Applicable
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2010-0007.htmlPatch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlBroken Link
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlBroken Link
- http://lists.vmware.com/pipermail/security-announce/2010/000090.htmlMailing List, Patch, Vendor Advisory
- http://secunia.com/advisories/39110Not Applicable
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2010-0007.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.