{"api_version":"1","generated_at":"2026-04-27T03:38:30+00:00","cve":"CVE-2010-1140","urls":{"html":"https://cve.report/CVE-2010-1140","api":"https://cve.report/api/cve/CVE-2010-1140.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-1140","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-1140"},"summary":{"title":"CVE-2010-1140","description":"The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2010-04-12 18:30:00","updated_at":"2013-05-15 03:07:00"},"problem_types":["CWE-264"],"metrics":[],"references":[{"url":"http://secunia.com/advisories/39206","name":"39206","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"VMware Products Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-201209-25.xml","name":"GLSA-201209-25","refsource":"GENTOO","tags":[],"title":"Gentoo Linux Documentation\n--\n  VMware Player, Server, Workstation: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.vmware.com/pipermail/security-announce/2010/000090.html","name":"[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","refsource":"MLIST","tags":["Patch","Vendor Advisory"],"title":"[Security-announce] VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1023834","name":"1023834","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - VMware Workstation and Player USB Service Lets Local Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html","name":"20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","refsource":"BUGTRAQ","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/39397","name":"39397","refsource":"BID","tags":[],"title":"VMware Hosted Products USB Service Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vmware.com/security/advisories/VMSA-2010-0007.html","name":"http://www.vmware.com/security/advisories/VMSA-2010-0007.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"VMSA-2010-0007.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html","name":"20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","refsource":"FULLDISC","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-1140","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1140","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"1140","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1140","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1140","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1140","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1140","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1140","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-1140","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-201209-25","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-201209-25.xml"},{"name":"39206","refsource":"SECUNIA","url":"http://secunia.com/advisories/39206"},{"name":"[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","refsource":"MLIST","url":"http://lists.vmware.com/pipermail/security-announce/2010/000090.html"},{"name":"20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html"},{"name":"http://www.vmware.com/security/advisories/VMSA-2010-0007.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2010-0007.html"},{"name":"39397","refsource":"BID","url":"http://www.securityfocus.com/bid/39397"},{"name":"1023834","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023834"},{"name":"20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html"}]}},"nvd":{"publishedDate":"2010-04-12 18:30:00","lastModifiedDate":"2013-05-15 03:07:00","problem_types":["CWE-264"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":6.9},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:workstation:7.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:player:3.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"1140","Ordinal":"43150","Title":"CVE-2010-1140","CVE":"CVE-2010-1140","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"1140","Ordinal":"1","NoteData":"The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk.","Type":"Description","Title":null},{"CveYear":"2010","CveId":"1140","Ordinal":"2","NoteData":"2010-04-12","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"1140","Ordinal":"3","NoteData":"2010-04-22","Type":"Other","Title":"Modified"}]}}}