Multiple VMware Products CVE-2013-1406 Local Privilege Escalation Vulnerability
BID:57867
Info
Multiple VMware Products CVE-2013-1406 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 57867 |
| Class: | Design Error |
| CVE: |
CVE-2013-1406 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2013 12:00AM |
| Updated: | Feb 04 2014 01:48AM |
| Credit: | Derek Soeder of Cylance, Inc. and Kostya Kortchinsky of Microsoft |
| Vulnerable: |
VMWare Workstation 8.0.2 VMWare Workstation 8.0.1 VMWare View 4.6.1 VMWare View 4.6 VMWare View 4.0 VMWare Fusion 4.1.2 VMWare Fusion 4.1.1 VMWare ESXi 5.0 VMWare ESXi 4.1 VMWare ESXi 4.0 VMWare ESX 4.1 VMWare ESX 4.0 |
| Not Vulnerable: | |
Discussion
Multiple VMware Products CVE-2013-1406 Local Privilege Escalation Vulnerability
Multiple VMware products are prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to gain elevated privileges on the target host operating system or guest operating system.
The following products are vulnerable:
VMware Workstation versions 8.x prior to 8.0.5 and 9.x prior to 9.0.1 running on Windows
VMware Fusion versions 4.x prior to 4.1.4 and 5.x prior to 5.0.2 running on Mac OS X
VMware View versions 4.x prior to 4.6.2 and 5.x prior to 5.1.2
VMware ESXi versions 4.0, 4.1, 5.0, 5.1
VMware ESX versions 4.0 and 4.1
Multiple VMware products are prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to gain elevated privileges on the target host operating system or guest operating system.
The following products are vulnerable:
VMware Workstation versions 8.x prior to 8.0.5 and 9.x prior to 9.0.1 running on Windows
VMware Fusion versions 4.x prior to 4.1.4 and 5.x prior to 5.0.2 running on Mac OS X
VMware View versions 4.x prior to 4.6.2 and 5.x prior to 5.1.2
VMware ESXi versions 4.0, 4.1, 5.0, 5.1
VMware ESX versions 4.0 and 4.1
Exploit / POC
Multiple VMware Products CVE-2013-1406 Local Privilege Escalation Vulnerability
An attacker requires local interactive access to exploit this issue.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker requires local interactive access to exploit this issue.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Multiple VMware Products CVE-2013-1406 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Multiple VMware Products CVE-2013-1406 Local Privilege Escalation Vulnerability
References:
References:
- VMware Homepage (VMware)