CVE-2014-1208
Summary
| CVE | CVE-2014-1208 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-17 21:55:19 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port. |
Risk And Classification
Primary CVSS: v2.0 3.3 from [email protected]
AV:A/AC:L/Au:N/C:N/I:N/A:P
EPSS: 0.002300000 probability, percentile 0.456230000 (date 2026-05-03)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:A/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Vmware | Esx | 4.0 | All | All | All |
| Operating System | Vmware | Esx | 4.1 | All | All | All |
| Operating System | Vmware | Esxi | 4.0 | All | All | All |
| Operating System | Vmware | Esxi | 4.0 | 1 | All | All |
| Operating System | Vmware | Esxi | 4.0 | 2 | All | All |
| Operating System | Vmware | Esxi | 4.0 | 3 | All | All |
| Operating System | Vmware | Esxi | 4.0 | 4 | All | All |
| Operating System | Vmware | Esxi | 4.1 | All | All | All |
| Operating System | Vmware | Esxi | 4.1 | 1 | All | All |
| Operating System | Vmware | Esxi | 4.1 | 2 | All | All |
| Operating System | Vmware | Esxi | 5.0 | All | All | All |
| Operating System | Vmware | Esxi | 5.0 | 1 | All | All |
| Operating System | Vmware | Esxi | 5.0 | 2 | All | All |
| Operating System | Vmware | Esxi | 5.1 | All | All | All |
| Application | Vmware | Fusion | 5.0 | All | All | All |
| Application | Vmware | Player | 5.0 | All | All | All |
| Application | Vmware | Workstation | 9.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMSA-2014-0001 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| VMware Workstation/Player/Fusion Bug in Handling Invalid VMX Ports Lets Local Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| osvdb.org/102197 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Multiple VMWare Products Local Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| VMware ESX/ESXi NFC and VMX Bugs Let Remote and Local Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.