7.2

CVE-2013-1406

The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Windows, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 does not properly restrict memory allocation by control code, which allows local users to gain privileges via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareWorkstation Version8.0
   MicrosoftWindows
VMwareWorkstation Version8.0.0.18997
   MicrosoftWindows
VMwareWorkstation Version8.0.1
   MicrosoftWindows
VMwareWorkstation Version8.0.1.27038
   MicrosoftWindows
VMwareWorkstation Version8.0.2
   MicrosoftWindows
VMwareWorkstation Version8.0.3
   MicrosoftWindows
VMwareWorkstation Version8.0.4
   MicrosoftWindows
VMwareWorkstation Version9.0
   MicrosoftWindows
VMwareFusion Version4.1
VMwareFusion Version4.1.1
VMwareFusion Version4.1.2
VMwareFusion Version4.1.3
VMwareFusion Version5.0
VMwareFusion Version5.0.1
VMwareView Version4.0.0
   MicrosoftWindows
VMwareView Version4.0.0 Updateu2
   MicrosoftWindows
VMwareView Version4.5
   MicrosoftWindows
VMwareView Version4.6.0
   MicrosoftWindows
VMwareView Version4.6.1
   MicrosoftWindows
VMwareView Version5.0
   MicrosoftWindows
VMwareView Version5.0.0
   MicrosoftWindows
VMwareView Version5.0.0 Updateu2
   MicrosoftWindows
VMwareView Version5.0.1
   MicrosoftWindows
VMwareView Version5.1.0
   MicrosoftWindows
VMwareView Version5.1.1
   MicrosoftWindows
VMwareESXi Version4.0
VMwareESXi Version4.0 Update1
VMwareESXi Version4.0 Update2
VMwareESXi Version4.0 Update3
VMwareESXi Version4.0 Update4
VMwareESXi Version4.1
VMwareESXi Version4.1 Update1
VMwareESXi Version4.1 Update2
VMwareESXi Version5.0
VMwareESXi Version5.0 Update1
VMwareESXi Version5.0 Update2
VMwareESXi Version5.1
VMwareEsx Version4.0
VMwareEsx Version4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.72
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.