Denial of Service in VMware Workstation and Player
CVE-2009-0177

Currently unrated

Key Information:

Vendor
Vmware
Vendor
CVE Published:
20 January 2009

Summary

The vmwarebase.dll component in VMware Workstation, Player, ACE, Server, and Fusion versions before the specified builds has a flaw that allows remote attackers to trigger a denial of service by sending overly long USER or PASS commands. This results in a crash of the vmware-authd service, potentially disrupting services and affecting availability.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.