Local Privilege Escalation Vulnerability in Hashicorp Vagrant VMware Fusion
CVE-2017-16839

7HIGH

Key Information:

Vendor
Hashicorp
Vendor
CVE Published:
29 March 2018

Summary

A local privilege escalation vulnerability exists in Hashicorp's Vagrant VMware Fusion version 5.0.4. This issue arises when VMware Fusion is not installed, allowing local users to exploit the flaw and potentially gain unauthorized root privileges. Organizations using this version should take immediate action to mitigate risks associated with unauthorized access and ensure proper configurations are in place.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.