Local Privilege Escalation in VMware Tools for OS X
CVE-2016-7080

7.8HIGH

Key Information:

Vendor
Vmware
Status
Vendor
CVE Published:
29 December 2016

Summary

The graphic acceleration functionalities within VMware Tools versions 9.x and 10.x prior to 10.0.9 on OS X are susceptible to a vulnerability that enables local users to exploit unspecified vectors, potentially allowing them to gain elevated privileges or causing a denial of service through a NULL pointer dereference. This issue poses a significant risk to users and systems relying on these versions of VMware Tools.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.