CVE-2010-4296
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- vmware/workstation · vmware/player · vmware/server · vmware/fusion
- Source
- cve@mitre.org
References
- http://lists.vmware.com/pipermail/security-announce/2010/000112.htmlMailing List, Vendor Advisory
- http://osvdb.org/69584Broken Link
- http://secunia.com/advisories/42453Broken Link, Vendor Advisory
- http://secunia.com/advisories/42482Broken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/514995/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45168Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024819Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024820Broken Link, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2010-0018.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/3116Broken Link, Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2010/000112.htmlMailing List, Vendor Advisory
- http://osvdb.org/69584Broken Link
- http://secunia.com/advisories/42453Broken Link, Vendor Advisory
- http://secunia.com/advisories/42482Broken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/514995/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45168Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024819Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024820Broken Link, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2010-0018.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/3116Broken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.