4.4

CVE-2007-5671

HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

Data is provided by the National Vulnerability Database (NVD)
VMwareAce Version1.0.0
VMwareAce Version1.0.1
VMwareAce Version1.0.2
VMwareAce Version1.0.3
VMwareAce Version1.0.4
VMwareEsx Server Version2.5.5
VMwarePlayer Version1.0.4
VMwareServer Version1.0.3
VMwareVmware Player Version1.0.0
VMwareVmware Player Version1.0.1
VMwareVmware Player Version1.0.2
VMwareVmware Player Version1.0.3
VMwareVmware Player Version1.0.5
VMwareVmware Server Version1.0.0
VMwareVmware Server Version1.0.1
VMwareVmware Server Version1.0.2
VMwareVmware Server Version1.0.4
VMwareVmware Workstation Version5.5.0
VMwareVmware Workstation Version5.5.2
VMwareVmware Workstation Version5.5.5
VMwareWorkstation Version5.5.1
VMwareWorkstation Version5.5.3
VMwareWorkstation Version5.5.4
VMwareEsx Version2.5.4
VMwareEsx Version3.0.0
VMwareEsx Version3.0.1
VMwareEsx Version3.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.31
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.