Local Privilege Escalation in Hashicorp Vagrant VMware Fusion
CVE-2017-16512

7.8HIGH

Key Information:

Vendor
Hashicorp
Vendor
CVE Published:
29 March 2018

Summary

The vagrant update process in certain versions of Hashicorp Vagrant VMware Fusion allows local users to exploit a crafted update request to gain unauthorized root privileges when no updates are currently available. This could potentially lead to serious security breaches as unauthorized users could escalate their privileges and gain access to sensitive system resources.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.