Local Privilege Escalation Vulnerability in VMware Tools
CVE-2007-5671

Currently unrated

Key Information:

Vendor
Vmware
Vendor
CVE Published:
5 June 2008

Summary

The vulnerability occurs in the HGFS.sys driver within the VMware Tools package, allowing users on a guest operating system to improperly validate input through specific IOCTL calls. This lack of validation enables these users to alter arbitrary memory locations within the kernel memory of the guest OS, potentially granting them elevated privileges. This vulnerability affects various versions of VMware Workstation, Player, ACE, Server, and ESX, necessitating timely updates to mitigate potential exploitation risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.