6.9
CVSSv2

CVE-2009-2267

Published: 02/11/2009 Updated: 10/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

VMware Workstation 6.5.x prior to 6.5.3 build 185404, VMware Player 2.5.x prior to 2.5.3 build 185404, VMware ACE 2.5.x prior to 2.5.3 build 185404, VMware Server 1.x prior to 1.0.10 build 203137 and 2.x prior to 2.0.2 build 203138, VMware Fusion 2.x prior to 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware ace 2.5.2

vmware server 2.0

vmware server 1.0.5

vmware server 1.0.6

vmware fusion 2.0.3

vmware fusion 2.0.4

vmware player 2.5

vmware server 1.0

vmware ace 2.5.0

vmware ace 2.5.1

vmware server 1.0.3

vmware server 1.0.4

vmware fusion 2.0.1

vmware fusion 2.0.2

vmware esx 3.0.3

vmware esx 2.5.5

vmware workstation 6.5.2

vmware player 2.5.2

vmware player 2.5.1

vmware server 1.0.1

vmware server 1.0.2

vmware server 1.0.9

vmware fusion 2.0

vmware esx 4.0

vmware esx 3.5

vmware workstation 6.5.0

vmware workstation 6.5.1

vmware server 2.0.1

vmware server 1.0.7

vmware server 1.0.8

vmware fusion 2.0.5

vmware esxi 3.5

vmware esxi 4.0

Exploits

Bugtraq ID: 36841 Class: Design Error Published: Oct 27 2009 12:00AM Updated: Oct 27 2009 09:18PM Credit: Tavis Ormandy and Julien Tinnes of the Google Security Team Vulnerable: VMWare Workstation 653 VMWare Workstation 652 build 156735 VMWare Workstation 652 VMWare Workstation 651 VMWare Workstation 65 build 118166 VMWare Server ...