CVE-2012-1508
The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vmware/esx · vmware/view · vmware/esxi
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0071.html
- http://osvdb.org/80115
- http://secunia.com/advisories/48378
- http://secunia.com/advisories/48379
- http://www.securityfocus.com/bid/52524
- http://www.securitytracker.com/id?1026814
- http://www.securitytracker.com/id?1026818
- http://www.vmware.com/security/advisories/VMSA-2012-0004.htmlVendor Advisory
- http://www.vmware.com/security/advisories/VMSA-2012-0005.htmlVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17183
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0071.html
- http://osvdb.org/80115
- http://secunia.com/advisories/48378
- http://secunia.com/advisories/48379
- http://www.securityfocus.com/bid/52524
- http://www.securitytracker.com/id?1026814
- http://www.securitytracker.com/id?1026818
- http://www.vmware.com/security/advisories/VMSA-2012-0004.htmlVendor Advisory
- http://www.vmware.com/security/advisories/VMSA-2012-0005.htmlVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17183
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.