7.2
CVSSv2

CVE-2010-4297

Published: 06/12/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The VMware Tools update functionality in VMware Workstation 6.5.x prior to 6.5.5 build 328052 and 7.x prior to 7.1.2 build 301548; VMware Player 2.5.x prior to 2.5.5 build 328052 and 3.1.x prior to 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x prior to 2.0.8 build 328035 and 3.1.x prior to 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS users to gain privileges on the guest OS via unspecified vectors, related to a "command injection" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware workstation 6.5.0

vmware workstation 7.1.2

vmware workstation 6.5.5

vmware workstation 7.1

vmware workstation 7.0.1

vmware workstation 6.5.3

vmware workstation 6.5.2

vmware workstation 6.5.1

vmware workstation 7.0

vmware workstation 7.1.1

vmware player 3.1

vmware player 2.5.5

vmware player 2.5.3

vmware player 2.5

vmware player 2.5.4

vmware player 3.1.1

vmware player 3.1.2

vmware player 2.5.1

vmware player 2.5.2

vmware fusion 2.0.6

vmware fusion 2.0

vmware fusion 2.0.1

vmware fusion 2.0.3

vmware fusion 3.1

vmware fusion 3.1.1

vmware fusion 2.0.2

vmware fusion 2.0.5

vmware fusion 2.0.4

vmware fusion 2.0.7

vmware fusion 2.0.8

vmware fusion 3.1.2

vmware esxi 4.1

vmware esxi 3.5

vmware esxi 4.0

vmware esx 3.5

vmware esx 4.0

vmware esx 4.1

Exploits

VMware Tools update OS Command Injection ======================================== 1 Advisory Information Advisory ID: BONSAI-2010-0110 Date published: Thu Dec 9, 2010 Vendors contacted: VMware Release mode: Coordinated release 2 Vulnerability Information Class: Injection Remotely Exploitable: Yes Locally Exploitable: Yes CVE Name: CVE-2010-4297 ...
VMware Tools update suffers from an operating system command injection vulnerability ...