KLA10733
Multiple vulnerabilities in VMware products
Обновлено: 17/06/2019
Дата обнаружения
07/01/2016
Уровень угрозы
High
Описание

Memory corruption vulnerability was found in VMware products. By exploiting this vulnerability malicious users can cause denial of service or gain privileges. This vulnerability can be exploited remotely via an unknown vectors.

NB: This vulnerability have no public CVSS rating so rating can be changed by the time.


Technical details

This vulnerability related to VMware Tools «Shared Folders» (HGFS) feature running on Microsoft Windows. As workaround you can remove this feature. This vulnerability doesn’t allow privileges escalation from guest to host.

Пораженные продукты

VMware Workstation 11 versions earlier than 11.1.2
VMware Player 7 versions earlier than 7.1.2
VMware Fusion 7 versions earlier than 7.1.2
VMware ESXi 6.0 versions earlier than patch ESXi600-201512102-SG
VMware ESXi 5.5 versions earlier than patch ESXi550-201512102-SG
VMware ESXi 5.1 versions earlier than patch ESXi510-201510102-SG
VMware ESXi 5.0 versions earlier than patch ESXi500-201510102-SG

Решение

Update to the latest version and after patch applied update VMware Tools in every Windows-based guest.
WMvare products download

Первичный источник обнаружения
VMware advisory
Оказываемое влияние
?
DoS 
[?]

PE 
[?]
Связанные продукты
VMware Workstation
VMware Player
VMware Fusion
CVE-IDS