5
CVSSv2

CVE-2009-3707

Published: 16/10/2009 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 prior to 7.0.1 build 227600 and 6.5.x prior to 6.5.4 build 246459, VMware Player 3.0 prior to 3.0.1 build 227600 and 2.5.x prior to 2.5.4 build 246459, VMware ACE 2.6 prior to 2.6.1 build 227600 and 2.5.x prior to 2.5.4 build 246459, and VMware Server 2.x allows remote malicious users to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware player 3.0.1

vmware player 2.5.4

vmware ace 2.5.2

vmware ace 2.5.1

vmware player 2.5.1

vmware ace 2.6.1

vmware player 3.0

vmware player 2.5.2

vmware workstation 7.0

vmware ace 2.6

vmware workstation 6.5.1

vmware ace 2.5.3

vmware workstation 6.5.4

vmware server 2.0.0

vmware workstation 6.5.0

vmware player 2.5

vmware ace 2.5.4

vmware workstation 7.0.1

vmware server 2.0.1

vmware workstation 6.5.2

vmware ace 2.5.0

vmware workstation 6.5.3

vmware server 2.0.2

vmware player 2.5.3

Exploits

source: wwwsecurityfocuscom/bid/36630/info VMware Player and Workstation are prone to a remote denial-of-service vulnerability because the applications fail to perform adequate validation checks on user-supplied input An attacker can exploit this issue to crash the 'vmware-authd' process, denying service to legitimate users NOTE: This ...