CVE-2009-3281
Summary
| CVE | CVE-2009-3281 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-16 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Vmware | Fusion | 1.0 | All | All | All |
| Application | Vmware | Fusion | 1.1 | All | All | All |
| Application | Vmware | Fusion | 1.1.1 | All | All | All |
| Application | Vmware | Fusion | 1.1.2 | All | All | All |
| Application | Vmware | Fusion | 1.1.3 | All | All | All |
| Application | Vmware | Fusion | 2.0 | All | All | All |
| Application | Vmware | Fusion | 2.0.1 | All | All | All |
| Application | Vmware | Fusion | 2.0.2 | All | All | All |
| Application | Vmware | Fusion | 2.0.3 | All | All | All |
| Application | Vmware | Fusion | 2.0.4 | All | All | All |
| Application | Vmware | Fusion | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Security-announce] VMSA-2009-0013 VMware Fusion resolves two security issues | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| VMware Fusion Denial of Service and Privilege Escalation - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VMSA-2009-0013 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| SecurityTracker.com Archives - VMware Fusion vmx86 Kernel Extension Bugs Let Local Host OS Users Gain Elevated Privileges and Deny Service on the Host System | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.