Lucene search

K
cve[email protected]CVE-2009-3281
HistoryOct 03, 2022 - 4:23 p.m.

CVE-2009-3281

2022-10-0316:23:56
CWE-264
web.nvd.nist.gov
29
cve-2009-3281
vmware fusion
privilege escalation
file permissions
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.3%

The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.

Affected configurations

NVD
Node
vmwarefusionRange≀2.0.5
OR
vmwarefusionMatch1.0
OR
vmwarefusionMatch1.1
OR
vmwarefusionMatch1.1.1
OR
vmwarefusionMatch1.1.2
OR
vmwarefusionMatch1.1.3
OR
vmwarefusionMatch2.0
OR
vmwarefusionMatch2.0.1
OR
vmwarefusionMatch2.0.2
OR
vmwarefusionMatch2.0.3
OR
vmwarefusionMatch2.0.4
AND
applemac_os_x

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.3%