{"api_version":"1","generated_at":"2026-07-24T22:14:41+00:00","cve":"CVE-2008-4279","urls":{"html":"https://cve.report/CVE-2008-4279","api":"https://cve.report/api/cve/CVE-2008-4279.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4279","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4279"},"summary":{"title":"CVE-2008-4279","description":"The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by triggering an exception that causes the virtual CPU to perform an indirect jump to a non-canonical address.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-10-06 19:54:36","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:L/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:C/I:C/A:C","baseScore":6.8,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/32157","name":"http://secunia.com/advisories/32157","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMware ESX / ESXi \"JMP\" Privilege Escalation Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1020991","name":"http://www.securitytracker.com/id?1020991","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"VMware 64-bit Hardware Emulation Bug Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2740","name":"http://www.vupen.com/english/advisories/2008/2740","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-October/064860.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-October/064860.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[Full-disclosure] VMware Emulation Flaw x64 Guest Privilege\tEscalation (1/2)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45668","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45668","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5929","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5929","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html","name":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"VMSA-2008-0016.2 - VMware","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32179","name":"http://secunia.com/advisories/32179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMware VirtualCenter Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2","name":"http://marc.info/?l=bugtraq&m=122331139823057&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded","name":"http://www.securityfocus.com/archive/1/497041/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31569","name":"http://www.securityfocus.com/bid/31569","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"VMware Products In-Guest Privilege Escalation and Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/32180","name":"http://secunia.com/advisories/32180","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMware ESX Server Sun Java JDK / JRE Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4279","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4279","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4279","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:08:34.960Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2"},{"name":"32157","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32157"},{"name":"20081004 VMware Emulation Flaw x64 Guest Privilege Escalation (1/2)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-October/064860.html"},{"name":"32179","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32179"},{"name":"ADV-2008-2740","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2740"},{"name":"32180","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32180"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html"},{"name":"vmware-esxesxi-jump-privilege-escalation(45668)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45668"},{"name":"31569","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31569"},{"name":"1020991","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1020991"},{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded"},{"name":"oval:org.mitre.oval:def:5929","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5929"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-10-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by triggering an exception that causes the virtual CPU to perform an indirect jump to a non-canonical address."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2"},{"name":"32157","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32157"},{"name":"20081004 VMware Emulation Flaw x64 Guest Privilege Escalation (1/2)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-October/064860.html"},{"name":"32179","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32179"},{"name":"ADV-2008-2740","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2740"},{"name":"32180","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32180"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html"},{"name":"vmware-esxesxi-jump-privilege-escalation(45668)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45668"},{"name":"31569","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31569"},{"name":"1020991","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1020991"},{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded"},{"name":"oval:org.mitre.oval:def:5929","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5929"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4279","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by triggering an exception that causes the virtual CPU to perform an indirect jump to a non-canonical address."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2"},{"name":"32157","refsource":"SECUNIA","url":"http://secunia.com/advisories/32157"},{"name":"20081004 VMware Emulation Flaw x64 Guest Privilege Escalation (1/2)","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-October/064860.html"},{"name":"32179","refsource":"SECUNIA","url":"http://secunia.com/advisories/32179"},{"name":"ADV-2008-2740","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2740"},{"name":"32180","refsource":"SECUNIA","url":"http://secunia.com/advisories/32180"},{"name":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html"},{"name":"vmware-esxesxi-jump-privilege-escalation(45668)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45668"},{"name":"31569","refsource":"BID","url":"http://www.securityfocus.com/bid/31569"},{"name":"1020991","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1020991"},{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded"},{"name":"oval:org.mitre.oval:def:5929","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5929"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4279","datePublished":"2008-10-06T18:00:00.000Z","dateReserved":"2008-09-26T00:00:00.000Z","dateUpdated":"2024-08-07T10:08:34.960Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-06 19:54:36","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:C/I:C/A:C","baseScore":6.8,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.1,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0","versionEndExcluding":"1.0.8","matchCriteriaId":"F29FCDD4-79B7-4047-997D-0AB10226072D"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0","versionEndExcluding":"2.0.5","matchCriteriaId":"F8CD1D7B-2D6F-4D48-8276-5C3285FF7B3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0","versionEndExcluding":"1.0.8","matchCriteriaId":"5DC7AFE3-A672-43B2-A77A-8C240198029B"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.5.8","matchCriteriaId":"6A47F4F7-B457-4F5B-B719-7A5741595456"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.0.5","matchCriteriaId":"F2B69FA6-E75A-4EDB-BD6C-41B560AABBC0"},{"vulnerable":true,"criteria":"cpe:2.3:o:vmware:esx:*:*:*:*:*:*:*:*","versionStartIncluding":"2.5.4","versionEndIncluding":"3.5","matchCriteriaId":"C75330AD-47BB-408C-A407-3685891A98BF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4279","Ordinal":"1","Title":"CVE-2008-4279","CVE":"CVE-2008-4279","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4279","Ordinal":"1","NoteData":"The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by triggering an exception that causes the virtual CPU to perform an indirect jump to a non-canonical address.","Type":"Description","Title":"CVE-2008-4279"},{"CveYear":"2008","CveId":"4279","Ordinal":"2","NoteData":"2008-10-06","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4279","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}