Lucene search

K
cve[email protected]CVE-2008-0967
HistoryJun 05, 2008 - 8:32 p.m.

CVE-2008-0967

2008-06-0520:32:00
web.nvd.nist.gov
34
cve-2008-0967
vmware
vulnerability
privilege escalation
nvd
linux
esxi
esx

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.

Affected configurations

NVD
Node
vmwareesx_serverMatch2.5.5
OR
vmwareesx_serverMatch3.1
OR
vmwareesx_serverMatch3.2
OR
vmwareesx_serverMatch3.3
OR
vmwareesx_serverMatch3.5
OR
vmwareesxiMatch3.5
OR
vmwareplayerMatch1.0.0
OR
vmwareplayerMatch1.0.1
OR
vmwareplayerMatch1.0.2
OR
vmwareplayerMatch1.0.3
OR
vmwareplayerMatch1.0.4
OR
vmwareplayerMatch1.0.5
OR
vmwareplayerMatch1.0.6
OR
vmwareplayerMatch2.0
OR
vmwareplayerMatch2.0.1
OR
vmwareplayerMatch2.0.2
OR
vmwareplayerMatch2.0.3
OR
vmwareserverMatch1.0.3
OR
vmwarevmware_serverMatch1.0.0
OR
vmwarevmware_serverMatch1.0.1
OR
vmwarevmware_serverMatch1.0.2
OR
vmwarevmware_serverMatch1.0.4
OR
vmwarevmware_serverMatch1.0.5
OR
vmwarevmware_workstationMatch5.5.0
OR
vmwarevmware_workstationMatch5.5.2
OR
vmwarevmware_workstationMatch5.5.5
OR
vmwarevmware_workstationMatch5.5.6
OR
vmwarevmware_workstationMatch6.0.1
OR
vmwarevmware_workstationMatch6.0.2
OR
vmwarevmware_workstationMatch6.0.3
OR
vmwareworkstationMatch5.5.1
OR
vmwareworkstationMatch5.5.3
OR
vmwareworkstationMatch5.5.4
OR
vmwareworkstationMatch6.0
OR
vmwareesxMatch3.0.0
OR
vmwareesxMatch3.0.1
OR
vmwareesxMatch3.0.2

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%