The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) prior to 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
hashicorp vagrant vmware fusion |