6.9
CVSSv2

CVE-2011-1787

Published: 06/06/2011 Updated: 14/11/2014
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x prior to 7.1.4, VMware Player 3.1.x prior to 3.1.4, VMware Fusion 3.1.x prior to 3.1.3, VMware ESXi 3.5 up to and including 4.1, and VMware ESX 3.0.3 up to and including 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware workstation 7.1.3

vmware workstation 7.1.1

vmware workstation 7.1.2

vmware player 3.1.2

vmware player 3.1.3

vmware player 3.1.1

vmware player 3.1

vmware fusion 3.1.1

vmware fusion 3.1.2

vmware fusion 3.1

vmware esxi 4.0

vmware esx 3.0.3

vmware esxi 3.5

vmware esxi 4.1

vmware esx 4.1

vmware esx 3.5

vmware esx 4.0

Vendor Advisories

Debian Bug report logs - #631506 CVE-2011-1787 Package: open-vm-tools; Maintainer for open-vm-tools is Bernd Zeimetz <bzed@debianorg>; Source for open-vm-tools is src:open-vm-tools (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Fri, 24 Jun 2011 13:27:02 UTC Severity: important Tags: sec ...