CVE-2005-4459
Summary
| CVE | CVE-2005-4459 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-21 20:03:00 UTC |
| Updated | 2026-07-07 22:01:29 UTC |
| Description | Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS: 0.141230000 probability, percentile 0.961370000 (date 2026-07-09)
Problem Types: CWE-119 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Ace | 1.0.1 | All | All | All |
| Application | Vmware | Gsx Server | 2.0 | All | All | All |
| Application | Vmware | Gsx Server | 2.0.1_build_2129 | All | All | All |
| Application | Vmware | Gsx Server | 2.5.1 | All | All | All |
| Application | Vmware | Gsx Server | 2.5.1_build_5336 | All | All | All |
| Application | Vmware | Gsx Server | 2.5.2 | All | All | All |
| Application | Vmware | Gsx Server | 3.0 | All | All | All |
| Application | Vmware | Gsx Server | 3.0_build_7592 | All | All | All |
| Application | Vmware | Gsx Server | 3.1 | All | All | All |
| Application | Vmware | Gsx Server | 3.2 | All | All | All |
| Application | Vmware | Player | 1.0.0 | All | All | All |
| Application | Vmware | Workstation | 3.2.1 | patch1 | All | All |
| Application | Vmware | Workstation | 3.4 | All | All | All |
| Application | Vmware | Workstation | 4.0 | All | All | All |
| Application | Vmware | Workstation | 4.0.1 | All | All | All |
| Application | Vmware | Workstation | 4.0.2 | All | All | All |
| Application | Vmware | Workstation | 4.5.2 | All | All | All |
| Application | Vmware | Workstation | 4.5.2_build_8848 | r4 | All | All |
| Application | Vmware | Workstation | 5.0.0_build_13124 | All | All | All |
| Application | Vmware | Workstation | 5.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Vulnerability Note VU#856689 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link |
| VMWare Remote Arbitrary Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Broken Link |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | URL Repurposed |
| SecurityReason - VMWare Workstation 5.5.0 <= build-18007 G SX Server Variants And Others | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| SecurityTracker.com Archives - VMware Flaw in NAT Function Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Permissions Required |
| [Full-disclosure] [ACSSEC-2005-11-25-0x1] VMWare Workstation 5.5.0 <= build-18007 G SX Server Variants And Others | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | Exploit |
| SecurityReason - VMware vulnerability in NAT networking | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| VMware Knowledge Base - Answer | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Broken Link |
| Secunia - Advisories - Gentoo update for vmware | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Secunia - Advisories - VMware NAT Networking Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link |
| Gentoo Linux Documentation -- VMware Workstation: Vulnerability in NAT networking | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.