VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, which allows user-assisted remote attackers to execute arbitrary code by tricking a Windows guest OS user into clicking on a file that is stored on a network share.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-emulation/vmware-server.Upgrade app-emulation/vmware-workstation.Upgrade app-emulation/vmware-player. | Oct 30, 2017 | Apr 12, 2010 |
| Vmsa 2010 0007 1 Windowsbased Vmware Tools Unsafe Library Loading Vulnerability | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESXi 4.0 to build number 236512Upgrade VMware ESX 3.5 to build number 213532Upgrade VMware ESXi 3.5 to build number 213532 | Sep 2, 2010 | Apr 12, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub