Information Disclosure in VMware Tools by VMware
CVE-2014-4200

Currently unrated

Key Information:

Vendor
Vmware
Vendor
CVE Published:
28 August 2014

Summary

A vulnerability exists in vm-support version 0.88 of VMware Tools, included with VMware Workstation up to version 10.0.3, due to improper file permissions being set to 0644 for the vm-support archive. This misconfiguration allows local users to potentially extract sensitive information from this archive, which could lead to unauthorized access to confidential data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.