7.9

CVE-2013-3519

lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.

Data is provided by the National Vulnerability Database (NVD)
VMwareESXi Version4.0
VMwareESXi Version4.1
VMwareESXi Version5.0
VMwareESXi Version5.1
VMwareWorkstation Version9.0
VMwareWorkstation Version9.0.1
VMwareWorkstation Version9.0.2
VMwareEsx Version4.0
VMwareEsx Version4.1
VMwarePlayer Version5.0
VMwarePlayer Version5.0.1
VMwarePlayer Version5.0.2
VMwareFusion Version5.0
VMwareFusion Version5.0.1
VMwareFusion Version5.0.2
VMwareFusion Version5.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.388
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.9 5.5 10
AV:A/AC:M/Au:N/C:C/I:C/A:C