CVE-2017-4922
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information.
Does this matter?
Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.
Description
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- vmware/vcenter server
- Source
- security@vmware.com
References
- http://www.securityfocus.com/bid/100012Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039013Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2017-0013.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/100012Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039013Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2017-0013.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.