Local Privilege Escalation Vulnerability in VMware Tools
CVE-2007-5671
Currently unrated
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 5 June 2008
Summary
The vulnerability occurs in the HGFS.sys driver within the VMware Tools package, allowing users on a guest operating system to improperly validate input through specific IOCTL calls. This lack of validation enables these users to alter arbitrary memory locations within the kernel memory of the guest OS, potentially granting them elevated privileges. This vulnerability affects various versions of VMware Workstation, Player, ACE, Server, and ESX, necessitating timely updates to mitigate potential exploitation risks.
References
Timeline
Vulnerability published
Vulnerability Reserved