7.2

CVE-2008-1363

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareAce Version >= 1.0 < 1.0.5
   MicrosoftWindows
VMwareAce Version >= 2.0 < 2.0.1
   MicrosoftWindows
VMwarePlayer Version >= 1.0.0 < 1.0.6
   MicrosoftWindows
VMwarePlayer Version >= 2.0 < 2.0.3
   MicrosoftWindows
VMwareServer Version >= 1.0 < 1.0.5
   MicrosoftWindows
VMwareWorkstation Version >= 5.5 < 5.5.6
   MicrosoftWindows
VMwareWorkstation Version >= 6.0 < 6.0.3
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C