CVE-2014-8370
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a…
Does this matter?
Lower severity and a low EPSS score (4.19%). Track it; it rarely justifies an emergency change on its own.
Description
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 4.19% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vmware/player · vmware/fusion · vmware/workstation · vmware/esxi
- Source
- cve@mitre.org
References
- http://jvn.jp/en/jp/JVN88252465/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000007Third Party Advisory, VDB Entry
- http://secunia.com/advisories/62551
- http://secunia.com/advisories/62605
- http://secunia.com/advisories/62669
- http://www.securityfocus.com/bid/72338Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031642Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031643Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2015-0001.htmlPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100933
- http://jvn.jp/en/jp/JVN88252465/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000007Third Party Advisory, VDB Entry
- http://secunia.com/advisories/62551
- http://secunia.com/advisories/62605
- http://secunia.com/advisories/62669
- http://www.securityfocus.com/bid/72338Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031642Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031643Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2015-0001.htmlPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100933
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.