CVE-2010-4296
Summary
| CVE | CVE-2010-4296 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-06 21:05:49 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Application | Vmware | Player | 3.1 | All | All | All |
| Application | Vmware | Player | 3.1.1 | All | All | All |
| Application | Vmware | Player | 3.1.2 | All | All | All |
| Application | Vmware | Workstation | 7.0 | All | All | All |
| Application | Vmware | Workstation | 7.0.1 | All | All | All |
| Application | Vmware | Workstation | 7.1 | All | All | All |
| Application | Vmware | Workstation | 7.1.1 | All | All | All |
| Application | Vmware | Workstation | 7.1.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple VMware products 'vmware-mount' Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Third Party Advisory |
| VMSA-2010-0018 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| [Security-announce] VMSA-2010-0018 VMware hosted products and ESX patches resolve multiple security issues | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Mailing List, Vendor Advisory |
| osvdb.org/69584 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| VMware Products "vmware-mount" Privilege Escalation Security Issues - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| SecurityTracker.com Archives - VMware Movie Decoder Heap Overflow in Decompression Routine Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| VMware Server Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| VMware Race Conditions and Input Validation Flaw Let Local Users on the Host Operating System Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.