VulnerabilityModified
CVE-2011-1126
VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory.
MEDIUM 6.9EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vmware/vix api · vmware/workstation
- Source
- cve@mitre.org
References
- http://lists.vmware.com/pipermail/security-announce/2011/000131.htmlVendor Advisory
- http://secunia.com/advisories/43885Vendor Advisory
- http://secunia.com/advisories/43943Vendor Advisory
- http://securityreason.com/securityalert/8173
- http://securitytracker.com/id?1025270
- http://www.securityfocus.com/archive/1/517240/100/0/threaded
- http://www.securityfocus.com/bid/47094
- http://www.vmware.com/security/advisories/VMSA-2011-0006.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2011/0816Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66472
- http://lists.vmware.com/pipermail/security-announce/2011/000131.htmlVendor Advisory
- http://secunia.com/advisories/43885Vendor Advisory
- http://secunia.com/advisories/43943Vendor Advisory
- http://securityreason.com/securityalert/8173
- http://securitytracker.com/id?1025270
- http://www.securityfocus.com/archive/1/517240/100/0/threaded
- http://www.securityfocus.com/bid/47094
- http://www.vmware.com/security/advisories/VMSA-2011-0006.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2011/0816Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66472
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.