VMware Tools 'HGFS.sys' Driver Local Privilege Escalation Vulnerability
BID:29549
Info
VMware Tools 'HGFS.sys' Driver Local Privilege Escalation Vulnerability
| Bugtraq ID: | 29549 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5761 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 04 2008 12:00AM |
| Credit: | iDefense and Stephen Fewer of Harmony Security |
| Vulnerable: |
VMWare Workstation 5.5.5 VMWare Workstation 5.5.4 build 44386 VMWare Workstation 5.5.4 VMWare Workstation 5.5.3 build 42958 VMWare Workstation 5.5.3 build 34685 VMWare Server 1.0.5 VMWare Server 1.0.4 VMWare Server 1.0.3 VMWare Server 1.0.2 VMWare Player 1.0.5 VMWare Player 1.0.4 VMWare Player 1.0.3 VMWare Player 1.0.2 VMWare Player 1.0.1 Build 19317 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.5 patch 2 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 2.5.4 patch 13 VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ACE 1.0.5 VMWare ACE 1.0.4 VMWare ACE 1.0.3 VMWare ACE 1.0.2 Build 19206 VMWare ACE 1.0.2 VMWare ACE 1.0 |
| Not Vulnerable: |
VMWare Workstation 5.5.6 Build 80404 VMWare Server 1.0.5 Build 80187 VMWare Player 1.0.6 Build 80404 VMWare ESX Server 2.5.4 Patch 16 VMWare ESX Server 2.5.5 patch 5 VMWare ACE 1.0.5 build 79846 |
Discussion
VMware Tools 'HGFS.sys' Driver Local Privilege Escalation Vulnerability
VMware Tools is prone to a local privilege-escalation vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary code with elevated privileges on the guest operating system. Successfully exploiting this issue may compromise the affected application and possibly the underlying computer.
The following VMware products are affected:
VMware Workstation 5 prior to 5.5.6 build 80404 for Microsoft Windows and Linux
VMware Player 1 prior to 1.0.6 build 80404 for Microsoft Windows and Linux
VMware ACE 1 prior to 1.0.5 build 79846
VMware Server prior to 1.0.5 build 80187 for Microsoft Windows and Linux
VMware ESX 3.0.2, 3.0.1, 2.5.5, and 2.5
VMware Tools is prone to a local privilege-escalation vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary code with elevated privileges on the guest operating system. Successfully exploiting this issue may compromise the affected application and possibly the underlying computer.
The following VMware products are affected:
VMware Workstation 5 prior to 5.5.6 build 80404 for Microsoft Windows and Linux
VMware Player 1 prior to 1.0.6 build 80404 for Microsoft Windows and Linux
VMware ACE 1 prior to 1.0.5 build 79846
VMware Server prior to 1.0.5 build 80187 for Microsoft Windows and Linux
VMware ESX 3.0.2, 3.0.1, 2.5.5, and 2.5
Exploit / POC
VMware Tools 'HGFS.sys' Driver Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
VMware Tools 'HGFS.sys' Driver Local Privilege Escalation Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
VMware Tools 'HGFS.sys' Driver Local Privilege Escalation Vulnerability
References:
References:
- VMware Homepage (VMware)
- iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Escalati (iDefense Labs
) - Re: iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Esca (iDefense Labs
) - VMware Tools HGFS Local Privilege Escalation Vulnerability (iDefense Labs)