Rapid7 Vulnerability & Exploit Database

VMware Player: VMware Tools Incorrect Folder Permissions Privilege Escalation (VMSA-2012-0007) (CVE-2012-1518)

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

VMware Player: VMware Tools Incorrect Folder Permissions Privilege Escalation (VMSA-2012-0007) (CVE-2012-1518)

Severity
8
CVSS
(AV:A/AC:L/Au:N/C:C/I:C/A:C)
Published
04/17/2012
Created
07/25/2018
Added
11/30/2013
Modified
05/09/2019

Description

VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.

Solution(s)

  • vmware-player-upgrade-3_1_6
  • vmware-player-upgrade-4_0_2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;