Lucene search

K
cveMitreCVE-2010-1141
HistoryApr 12, 2010 - 6:30 p.m.

CVE-2010-1141

2010-04-1218:30:00
CWE-264
mitre
web.nvd.nist.gov
38
cve-2010-1141
vmware tools
vmware workstation
vmware player
vmware ace
vmware server
vmware fusion
vmware esxi
vmware esx
remote code execution
nvd

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.8

Confidence

High

EPSS

0.028

Percentile

90.6%

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, which allows user-assisted remote attackers to execute arbitrary code by tricking a Windows guest OS user into clicking on a file that is stored on a network share.

Affected configurations

Nvd
Node
vmwareworkstationMatch6.5.0
OR
vmwareworkstationMatch6.5.1
OR
vmwareworkstationMatch6.5.2
OR
vmwareworkstationMatch6.5.3
AND
microsoftwindows
Node
vmwareplayerMatch2.5
OR
vmwareplayerMatch2.5.1
OR
vmwareplayerMatch2.5.2
OR
vmwareplayerMatch2.5.3
AND
microsoftwindows
Node
vmwareaceMatch2.5.0
OR
vmwareaceMatch2.5.1
OR
vmwareaceMatch2.5.2
OR
vmwareaceMatch2.5.3
AND
microsoftwindows
Node
vmwareserverMatch2.0.0
OR
vmwareserverMatch2.0.1
OR
vmwareserverMatch2.0.2
AND
microsoftwindows
Node
vmwarefusionMatch2.0
OR
vmwarefusionMatch2.0.1
OR
vmwarefusionMatch2.0.2
OR
vmwarefusionMatch2.0.3
OR
vmwarefusionMatch2.0.4
OR
vmwarefusionMatch2.0.5
OR
vmwarefusionMatch3.0
AND
microsoftwindows
Node
vmwareesxiMatch3.5
OR
vmwareesxiMatch4.0
AND
microsoftwindows
Node
vmwareesxMatch2.5.5
OR
vmwareesxMatch3.0.3
OR
vmwareesxMatch3.5
OR
vmwareesxMatch4.0
AND
microsoftwindows
VendorProductVersionCPE
vmwareworkstation6.5.0cpe:2.3:a:vmware:workstation:6.5.0:*:*:*:*:*:*:*
vmwareworkstation6.5.1cpe:2.3:a:vmware:workstation:6.5.1:*:*:*:*:*:*:*
vmwareworkstation6.5.2cpe:2.3:a:vmware:workstation:6.5.2:*:*:*:*:*:*:*
vmwareworkstation6.5.3cpe:2.3:a:vmware:workstation:6.5.3:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
vmwareplayer2.5cpe:2.3:a:vmware:player:2.5:*:*:*:*:*:*:*
vmwareplayer2.5.1cpe:2.3:a:vmware:player:2.5.1:*:*:*:*:*:*:*
vmwareplayer2.5.2cpe:2.3:a:vmware:player:2.5.2:*:*:*:*:*:*:*
vmwareplayer2.5.3cpe:2.3:a:vmware:player:2.5.3:*:*:*:*:*:*:*
vmwareace2.5.0cpe:2.3:a:vmware:ace:2.5.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 291

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.8

Confidence

High

EPSS

0.028

Percentile

90.6%