CVE-2012-2450
Summary
| CVE | CVE-2012-2450 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-05-04 16:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS. |
Risk And Classification
Primary CVSS: v2.0 9 from [email protected]
AV:N/AC:L/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Vmware | Esx | 3.5 | All | All | All |
| Operating System | Vmware | Esx | 3.5 | update1 | All | All |
| Operating System | Vmware | Esx | 3.5 | update2 | All | All |
| Operating System | Vmware | Esx | 3.5 | update3 | All | All |
| Operating System | Vmware | Esx | 4.0 | All | All | All |
| Operating System | Vmware | Esx | 4.1 | All | All | All |
| Operating System | Vmware | Esxi | 3.5 | All | All | All |
| Operating System | Vmware | Esxi | 3.5 | 1 | All | All |
| Operating System | Vmware | Esxi | 4.0 | All | All | All |
| Operating System | Vmware | Esxi | 4.0 | 1 | All | All |
| Operating System | Vmware | Esxi | 4.0 | 2 | All | All |
| Operating System | Vmware | Esxi | 4.0 | 3 | All | All |
| Operating System | Vmware | Esxi | 4.0 | 4 | All | All |
| Operating System | Vmware | Esxi | 4.1 | All | All | All |
| Operating System | Vmware | Esxi | 4.1 | 1 | All | All |
| Operating System | Vmware | Esxi | 4.1 | 2 | All | All |
| Operating System | Vmware | Esxi | 5.0 | All | All | All |
| Application | Vmware | Fusion | 4.0 | All | All | All |
| Application | Vmware | Fusion | 4.0.1 | All | All | All |
| Application | Vmware | Fusion | 4.0.2 | All | All | All |
| Application | Vmware | Fusion | 4.1 | All | All | All |
| Application | Vmware | Fusion | 4.1.1 | All | All | All |
| Application | Vmware | Player | 4.0 | All | All | All |
| Application | Vmware | Player | 4.0.1 | All | All | All |
| Application | Vmware | Player | 4.0.2 | All | All | All |
| Application | Vmware | Workstation | 8.0 | All | All | All |
| Application | Vmware | Workstation | 8.0.1 | All | All | All |
| Application | Vmware | Workstation | 8.0.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware ESX/ESXi Virtual Floppy Configuration and SCSI Device Registration Flaws Let Local Guest Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| osvdb.org/81695 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| VMware Multiple Products Multiple Memory Corruption Privilege Escalation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VMSA-2012-0009.2 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.