VMware vCenter Server CVE-2017-4919 Local Authentication Bypass Vulnerability
BID:100102
Info
VMware vCenter Server CVE-2017-4919 Local Authentication Bypass Vulnerability
| Bugtraq ID: | 100102 |
| Class: | Access Validation Error |
| CVE: |
CVE-2017-4919 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 27 2017 12:00AM |
| Updated: | Jul 27 2017 12:00AM |
| Credit: | Ofri Ziv and Itamar Tal from Guardicore. |
| Vulnerable: |
VMWare vCenter Server 6.5 VMWare vCenter Server 6.0 VMWare vCenter Server 5.5 |
| Not Vulnerable: | |
Discussion
VMware vCenter Server CVE-2017-4919 Local Authentication Bypass Vulnerability
VMware vCenter Server is prone to a local authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access. This may lead to further attacks.
VMware vCenter Server is prone to a local authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access. This may lead to further attacks.
Exploit / POC
VMware vCenter Server CVE-2017-4919 Local Authentication Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
VMware vCenter Server CVE-2017-4919 Local Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
VMware vCenter Server CVE-2017-4919 Local Authentication Bypass Vulnerability
References:
References: