The VMware Tools update functionality in VMware Workstation 6.5.x before...
Vulnerability Description
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS users to gain privileges on the guest OS via unspecified vectors, related to a "command injection" issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4297
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.vmware.com/pipermail/security-announce/2010/000112.html
- http://osvdb.org/69590
- http://www.vmware.com/security/advisories/VMSA-2010-0018.html
- http://www.securityfocus.com/bid/45166
- http://www.securityfocus.com/archive/1/514995/100/0/threaded
- http://secunia.com/advisories/42480
- http://www.securitytracker.com/id?1024819
- http://secunia.com/advisories/42482
- http://www.vupen.com/english/advisories/2010/3116
- http://www.securitytracker.com/id?1024820
More from vmware
View All →Affected Vendor
vmware
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.