CVE-2008-1363
Summary
| CVE | CVE-2008-1363 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-20 00:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| VMware Player Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| [Security-announce] VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| VMware Server Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| VMSA-2008-0005.1 - VMware | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| VMware ACE Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - VMware VMX Configuration File Access Controls Lets Local Users Gain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| VMware Workstation 6 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| SecurityReason - VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| VMware Player Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| VMware Workstation 5.5 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.