KLA10733
Multiple vulnerabilities in VMware products
Updated: 11/06/2018
CVSS
?
6.5
Detect date
?
01/07/2016
Severity
?
High
Description

Memory corruption vulnerability was found in VMware products. By exploiting this vulnerability malicious users can cause denial of service or gain privileges. This vulnerability can be exploited remotely via an unknown vectors.

NB: This vulnerability have no public CVSS rating so rating can be changed by the time.


Technical details

This vulnerability related to VMware Tools “Shared Folders” (HGFS) feature running on Microsoft Windows. As workaround you can remove this feature. This vulnerability doesn’t allow privileges escalation from guest to host.

Affected products

VMware Workstation 11 versions earlier than 11.1.2
VMware Player 7 versions earlier than 7.1.2
VMware Fusion 7 versions earlier than 7.1.2
VMware ESXi 6.0 versions earlier than patch ESXi600-201512102-SG
VMware ESXi 5.5 versions earlier than patch ESXi550-201512102-SG
VMware ESXi 5.1 versions earlier than patch ESXi510-201510102-SG
VMware ESXi 5.0 versions earlier than patch ESXi500-201510102-SG

Solution

Update to the latest version and after patch applied update VMware Tools in every Windows-based guest.
WMvare products download

Original advisories

VMware advisory

Impacts
?
DoS 
[?]

PE 
[?]
Related products
VMware Workstation
VMware Player
VMware Fusion
CVE-IDS
?

CVE-2015-6933