Rapid7 Vulnerability & Exploit Database

VMware Workstation: Setting ActiveX killbit (VMSA-2008-0014) (CVE-2007-5438)

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

VMware Workstation: Setting ActiveX killbit (VMSA-2008-0014) (CVE-2007-5438)

Severity
2
CVSS
(AV:L/AC:M/Au:N/C:N/I:N/A:P)
Published
10/12/2007
Created
07/25/2018
Added
02/18/2014
Modified
10/24/2016

Description

Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 might allow local users to cause a denial of service to the Virtual Disk Mount Service (vmount2.exe), related to the ConnectPopulatedDiskEx function.

Solution(s)

  • vmware-workstation-upgrade-5_5_8
  • vmware-workstation-upgrade-6_0_5

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;