Lucene search

K
kasperskyKaspersky LabKLA10385
HistoryOct 07, 2011 - 12:00 a.m.

KLA10385 ACE vulnerability in VMware

2011-10-0700:00:00
Kaspersky Lab
threats.kaspersky.com
19

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.277 Low

EPSS

Percentile

96.8%

A buffer overflow was found in VMware products. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed ISO image.

Original advisories

VMware bulletin

Related products

VMware-Workstation

VMware-Player

VMware-Fusion

CVE list

CVE-2011-3868 critical

Solution

Update to latest version

VMWare Products

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • VMware Workstation versions 7.1.4 and earlierVMware Player versions 3.1.4 and earlierVMware Fusion versions 3.1.2 and earlier

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.277 Low

EPSS

Percentile

96.8%