CVE-2017-11741
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- hashicorp/vagrant vmware fusion
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Aug/0Mailing List, Third Party Advisory
- https://m4.rkw.io/blog/cve201711741-local-root-privesc-in-hashicorp-vagrantvmwarefusion--4023.htmlExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/43224/
- http://seclists.org/fulldisclosure/2017/Aug/0Mailing List, Third Party Advisory
- https://m4.rkw.io/blog/cve201711741-local-root-privesc-in-hashicorp-vagrantvmwarefusion--4023.htmlExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/43224/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.