Lucene search

K
nvd[email protected]NVD:CVE-2007-5671
HistoryJun 05, 2008 - 8:32 p.m.

CVE-2007-5671

2008-06-0520:32:00
CWE-20
web.nvd.nist.gov

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

Affected configurations

NVD
Node
vmwareaceMatch1.0.0
OR
vmwareaceMatch1.0.1
OR
vmwareaceMatch1.0.2
OR
vmwareaceMatch1.0.3
OR
vmwareaceMatch1.0.4
OR
vmwareesx_serverMatch2.5.5
OR
vmwareplayerMatch1.0.4
OR
vmwareserverMatch1.0.3
OR
vmwarevmware_playerMatch1.0.0
OR
vmwarevmware_playerMatch1.0.1
OR
vmwarevmware_playerMatch1.0.2
OR
vmwarevmware_playerMatch1.0.3
OR
vmwarevmware_playerMatch1.0.5
OR
vmwarevmware_serverMatch1.0.0
OR
vmwarevmware_serverMatch1.0.1
OR
vmwarevmware_serverMatch1.0.2
OR
vmwarevmware_serverMatch1.0.4
OR
vmwarevmware_workstationMatch5.5.0
OR
vmwarevmware_workstationMatch5.5.2
OR
vmwarevmware_workstationMatch5.5.5
OR
vmwareworkstationMatch5.5.1
OR
vmwareworkstationMatch5.5.3
OR
vmwareworkstationMatch5.5.4
OR
vmwareesxMatch2.5.4
OR
vmwareesxMatch3.0.0
OR
vmwareesxMatch3.0.1
OR
vmwareesxMatch3.0.2

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%