4.4
CVE-2007-5671
- EPSS 0.12%
- Veröffentlicht 05.06.2008 20:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Esx Server Version2.5.5
VMware ≫ Vmware Player Version1.0.0
VMware ≫ Vmware Player Version1.0.1
VMware ≫ Vmware Player Version1.0.2
VMware ≫ Vmware Player Version1.0.3
VMware ≫ Vmware Player Version1.0.5
VMware ≫ Vmware Server Version1.0.0
VMware ≫ Vmware Server Version1.0.1
VMware ≫ Vmware Server Version1.0.2
VMware ≫ Vmware Server Version1.0.4
VMware ≫ Vmware Workstation Version5.5.0
VMware ≫ Vmware Workstation Version5.5.2
VMware ≫ Vmware Workstation Version5.5.5
VMware ≫ Workstation Version5.5.1
VMware ≫ Workstation Version5.5.3
VMware ≫ Workstation Version5.5.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.31 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.4 | 3.4 | 6.4 |
AV:L/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.