Lucene search

K
kasperskyKaspersky LabKLA10384
HistoryDec 19, 2012 - 12:00 a.m.

KLA10384 RLF vulnerability in VMware View

2012-12-1900:00:00
Kaspersky Lab
threats.kaspersky.com
14

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%

A directory traversal vulnerability was found in VMware Viewer. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via unspecified vectors.

Original advisories

VMware bulletin

Related products

VMware-View

CVE list

CVE-2012-5978 critical

Solution

Update to latest version

VMWare Products

Impacts

  • RLF

Read Local Files. Exploitation of vulnerabilities with this impact can lead to reading some inaccessible files. Files that can be read depends on conัrete program errors.

Affected Products

  • VMware View 4 versions earlier than 4.6.2VMware Viewย 5ย versions earlier thanย 5.1.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%