VulnerabilityModified
CVE-2010-1140
The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk.
MEDIUM 6.9EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vmware/workstation · vmware/player
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html
- http://lists.vmware.com/pipermail/security-announce/2010/000090.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/39206Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xml
- http://securitytracker.com/id?1023834
- http://www.securityfocus.com/bid/39397
- http://www.vmware.com/security/advisories/VMSA-2010-0007.htmlPatch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html
- http://lists.vmware.com/pipermail/security-announce/2010/000090.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/39206Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xml
- http://securitytracker.com/id?1023834
- http://www.securityfocus.com/bid/39397
- http://www.vmware.com/security/advisories/VMSA-2010-0007.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.