4.9
CVSSv2

CVE-2008-3761

Published: 21/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

hcmon.sys in VMware Workstation 6.5.1 and previous versions, VMware Player 2.5.1 and previous versions, VMware ACE 2.5.1 and previous versions, and VMware Server 1.0.x prior to 1.0.9 build 156507 and 2.0.x prior to 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware vmware workstation 6.0.0.45731

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - Orange Bat advisory - Name : VMWare Workstation (hcmonsys 60045731) Class : DoS Published : 2008-08-17 Credit : g_ (g_ # orange-bat # com) - - Details - Fails to sanitize pointers sent from usermode with METHOD_NEITHER hcmonsys: text:00011606 loc_1160 ...