Lucene search

K
cveMitreCVE-2011-1126
HistoryApr 04, 2011 - 12:27 p.m.

CVE-2011-1126

2011-04-0412:27:38
CWE-264
mitre
web.nvd.nist.gov
28
vmware
vmrun
vix api
privilege escalation
linux
security vulnerability

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%

VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory.

Affected configurations

Nvd
Node
vmwarevix_apiMatch1.0
OR
vmwarevix_apiMatch1.1
OR
vmwarevix_apiMatch1.1.1
OR
vmwarevix_apiMatch1.1.2
OR
vmwarevix_apiMatch1.1.3
OR
vmwarevix_apiMatch1.1.4
OR
vmwarevix_apiMatch1.1.5
OR
vmwarevix_apiMatch1.6.0
OR
vmwarevix_apiMatch1.6.1
OR
vmwarevix_apiMatch1.7
OR
vmwarevix_apiMatch1.8
OR
vmwarevix_apiMatch1.8.1
OR
vmwarevix_apiMatch1.9
AND
linuxlinux_kernel
Node
vmwareworkstationMatch6.5.0
OR
vmwareworkstationMatch6.5.1
OR
vmwareworkstationMatch6.5.2
OR
vmwareworkstationMatch6.5.3
OR
vmwareworkstationMatch6.5.4
OR
vmwareworkstationMatch6.5.5
OR
vmwareworkstationMatch7.0
OR
vmwareworkstationMatch7.0.1
OR
vmwareworkstationMatch7.1
OR
vmwareworkstationMatch7.1.1
OR
vmwareworkstationMatch7.1.2
OR
vmwareworkstationMatch7.1.3
AND
linuxlinux_kernel
VendorProductVersionCPE
vmwarevix_api1.0cpe:2.3:a:vmware:vix_api:1.0:*:*:*:*:*:*:*
vmwarevix_api1.1cpe:2.3:a:vmware:vix_api:1.1:*:*:*:*:*:*:*
vmwarevix_api1.1.1cpe:2.3:a:vmware:vix_api:1.1.1:*:*:*:*:*:*:*
vmwarevix_api1.1.2cpe:2.3:a:vmware:vix_api:1.1.2:*:*:*:*:*:*:*
vmwarevix_api1.1.3cpe:2.3:a:vmware:vix_api:1.1.3:*:*:*:*:*:*:*
vmwarevix_api1.1.4cpe:2.3:a:vmware:vix_api:1.1.4:*:*:*:*:*:*:*
vmwarevix_api1.1.5cpe:2.3:a:vmware:vix_api:1.1.5:*:*:*:*:*:*:*
vmwarevix_api1.6.0cpe:2.3:a:vmware:vix_api:1.6.0:*:*:*:*:*:*:*
vmwarevix_api1.6.1cpe:2.3:a:vmware:vix_api:1.6.1:*:*:*:*:*:*:*
vmwarevix_api1.7cpe:2.3:a:vmware:vix_api:1.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%