VMware Products Trap Flag In-Guest Privilege Escalation Vulnerability
BID:32168
Info
VMware Products Trap Flag In-Guest Privilege Escalation Vulnerability
| Bugtraq ID: | 32168 |
| Class: | Unknown |
| CVE: |
CVE-2008-4915 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 06 2008 12:00AM |
| Updated: | Oct 01 2012 07:01PM |
| Credit: | Derek Soeder |
| Vulnerable: |
VMWare Workstation 6.0.5 build 109488 VMWare Workstation 6.0.5 VMWare Workstation 6.0.4 build 93057 VMWare Workstation 6.0.4 VMWare Workstation 6.0.3 Build 80004 VMWare Workstation 6.0.3 VMWare Workstation 6.0.2 VMWare Workstation 6.0.1 VMWare Workstation 6.0 VMWare Workstation 5.5.8 build 108000 VMWare Workstation 5.5.8 VMWare Workstation 5.5.7 build 91707 VMWare Workstation 5.5.7 VMWare Workstation 5.5.6 Build 80404 VMWare Workstation 5.5.6 VMWare Workstation 5.5.5 VMWare Workstation 5.5.4 build 44386 VMWare Workstation 5.5.4 VMWare Workstation 5.5.3 build 42958 VMWare Workstation 5.5.3 build 34685 VMWare Workstation 6.0.0.45731 VMWare Server 1.0.7 build 108231 VMWare Server 1.0.7 VMWare Server 1.0.6 build 91891 VMWare Server 1.0.6 VMWare Server 1.0.5 Build 80187 VMWare Server 1.0.5 VMWare Server 1.0.4 VMWare Server 1.0.3 VMWare Server 1.0.2 VMWare Player 2.0.5 build 109488 VMWare Player 2.0.5 VMWare Player 2.0.4 build 93057 VMWare Player 2.0.4 VMWare Player 2.0.3 Build 80004 VMWare Player 2.0.2 VMWare Player 2.0.1 VMWare Player 2.0 VMWare Player 1.0.8 build 108000 VMWare Player 1.0.8 VMWare Player 1.0.7 build 91707 VMWare Player 1.0.6 Build 80404 VMWare Player 1.0.6 VMWare Player 1.0.5 VMWare Player 1.0.4 VMWare Player 1.0.3 VMWare Player 1.0.2 VMWare Player 1.0.1 Build 19317 VMWare ESXi Server 3.5 VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.2 VMWare ESX Server 2.5.5 patch 8 VMWare ESX Server 2.5.5 patch 6 VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.5 patch 2 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 patch 19 VMWare ESX Server 2.5.4 Patch 17 VMWare ESX Server 2.5.4 Patch 16 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 2.5.4 patch 13 VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 3.5 VMWare ESX Server 2.5.5 patch 5 VMWare ACE 2.0.5 build 109488 VMWare ACE 2.0.5 VMWare ACE 2.0.3 VMWare ACE 2.0.2 build 93057 VMWare ACE 2.0.2 VMWare ACE 2.0.1 VMWare ACE 2.0 VMWare ACE 1.0.7 build 108880 VMWare ACE 1.0.7 VMWare ACE 1.0.5 VMWare ACE 1.0.4 VMWare ACE 1.0.3 VMWare ACE 1.0.2 Build 19206 VMWare ACE 1.0.2 VMWare ACE 1.0 VMWare ACE 1.0.5 build 79846 Gentoo Linux |
| Not Vulnerable: |
VMWare Workstation 6.5 build 118166 VMWare Workstation 5.5.9 build 126128 VMWare Server 1.0.8 build 126538 VMWare Player 2.5 build 118166 VMWare Player 1.0.9 build 126128 VMWare ESX Server 2.5.5 patch 10 VMWare ESX Server 2.5.4 patch 21 VMWare ACE 2.5 build 118166 VMWare ACE 1.0.8 build 125922 |
Discussion
VMware Products Trap Flag In-Guest Privilege Escalation Vulnerability
VMware products are prone to a privilege-escalation vulnerability caused by an unspecified flaw in the CPU hardware emulation.
Successful exploits may allow local attackers to elevate privileges in a guest operating system.
These issues affect versions prior to:
Workstation 6.5.0 build 118166
Workstation 5.5.9 build 126128
Player 2.5.0 build 118166
Player 1.0.9 build 126128
ACE Windows 2.5.0 build 118166
ACE Windows 1.0.8 build 125922
Server 1.0.8 build 126538
ESXi 3.5 ESXe350-200810401-O-UG
ESX 3.5 ESX350-200810201-UG
ESX 3.0.3 ESX303-200810501-BG
ESX 3.0.2 ESX-1006680
ESX 2.5.5 upgrade patch 10
ESX 2.5.4 upgrade patch 21
VMware products are prone to a privilege-escalation vulnerability caused by an unspecified flaw in the CPU hardware emulation.
Successful exploits may allow local attackers to elevate privileges in a guest operating system.
These issues affect versions prior to:
Workstation 6.5.0 build 118166
Workstation 5.5.9 build 126128
Player 2.5.0 build 118166
Player 1.0.9 build 126128
ACE Windows 2.5.0 build 118166
ACE Windows 1.0.8 build 125922
Server 1.0.8 build 126538
ESXi 3.5 ESXe350-200810401-O-UG
ESX 3.5 ESX350-200810201-UG
ESX 3.0.3 ESX303-200810501-BG
ESX 3.0.2 ESX-1006680
ESX 2.5.5 upgrade patch 10
ESX 2.5.4 upgrade patch 21
Exploit / POC
VMware Products Trap Flag In-Guest Privilege Escalation Vulnerability
The original reporter has developed a working proof-of-concept exploit for this issue. Currently we are not aware of any public exploit code. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The original reporter has developed a working proof-of-concept exploit for this issue. Currently we are not aware of any public exploit code. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
VMware Products Trap Flag In-Guest Privilege Escalation Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
VMware Products Trap Flag In-Guest Privilege Escalation Vulnerability
References:
References: