CVE-2015-6933
Summary
| CVE | CVE-2015-6933 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-09 02:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors. |
Risk And Classification
Primary CVSS: v3.0 6.3 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Problem Types: CWE-284 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.3 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| 2.0 | [email protected] | Primary | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Vmware | Esxi | 5.0 | All | All | All |
| Operating System | Vmware | Esxi | 5.0 | 1 | All | All |
| Operating System | Vmware | Esxi | 5.0 | 2 | All | All |
| Operating System | Vmware | Esxi | 5.1 | All | All | All |
| Operating System | Vmware | Esxi | 5.1 | 1 | All | All |
| Operating System | Vmware | Esxi | 5.5 | All | All | All |
| Operating System | Vmware | Esxi | 6.0 | All | All | All |
| Application | Vmware | Fusion | 7.0 | All | All | All |
| Application | Vmware | Fusion | 7.1 | All | All | All |
| Application | Vmware | Fusion | 7.1.1 | All | All | All |
| Application | Vmware | Player | 7.0 | All | All | All |
| Application | Vmware | Player | 7.1 | All | All | All |
| Application | Vmware | Player | 7.1.1 | All | All | All |
| Application | Vmware | Workstation | 11.0 | All | All | All |
| Application | Vmware | Workstation | 11.1 | All | All | All |
| Application | Vmware | Workstation | 11.1.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware ESXi VMware Tools Shared Folders Lets Local Users on a Windows-Based Guest System Gain Elevated Privileges on the Guest System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMware Workstation, Player, and Fusion VMware Tools Shared Folders Lets Local Users on a Windows-Based Guest System Gain Elevated Privileges on the Guest System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMSA-2016-0001 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.