CVE-2010-1140
Summary
| CVE | CVE-2010-1140 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-12 18:30:00 UTC |
| Updated | 2013-05-15 03:07:00 UTC |
| Description | The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Application | Vmware | Player | 3.0 | All | All | All |
| Application | Vmware | Player | 3.0 | All | All | All |
| Application | Vmware | Workstation | 7.0 | All | All | All |
| Application | Vmware | Workstation | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Products Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| [Security-announce] VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues | MLIST | lists.vmware.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - VMware Workstation and Player USB Service Lets Local Users Gain Elevated Privileges | SECTRACK | securitytracker.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | BUGTRAQ | archives.neohapsis.com | |
| VMware Hosted Products USB Service Local Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| VMSA-2010-0007.1 | CONFIRM | www.vmware.com | Patch, Vendor Advisory |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | FULLDISC | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.