Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-5671
HistoryJun 05, 2008 - 12:00 a.m.

CVE-2007-5671

2008-06-0500:00:00
ubuntu.com
ubuntu.com
13

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

0.001 Low

EPSS

Percentile

26.7%

HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6
build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before
1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX
2.5.4 through 3.0.2 does not properly validate arguments in user-mode
METHOD_NEITHER IOCTLs to the \.\hgfs device, which allows guest OS users
to modify arbitrary memory locations in guest kernel memory and gain
privileges.

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

0.001 Low

EPSS

Percentile

26.7%