7
CVSSv3

CVE-2017-15884

Published: 31/10/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp vagrant vmware fusion 5.0.0

Exploits

# After three CVEs and multiple exploits disclosed to Hashicorp they have finally upped their game with this plugin Now the previously vulnerable non-root-owned # ruby code that get executed as root by the sudo helper is no more and the sudo helper itself is one static Go binary with tightly-controlled parameters that # can't (as far as I can tell ...