CVE-2007-5438
published 2007-10-13CVE-2007-5438: Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.37%
29.2th percentile
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 might allow local users to cause a denial of service to the Virtual Disk Mount Service (vmount2.exe), related to the ConnectPopulatedDiskEx function.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
| vmware | vmware_player | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3x3h-397m-6f9w: Unspecified vulnerability in a certain ActiveX control in Reconfig
ghsa_unreviewed·2022-05-01
CVE-2007-5438 [LOW] CWE-20 GHSA-3x3h-397m-6f9w: Unspecified vulnerability in a certain ActiveX control in Reconfig
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 might allow local users to cause a denial of service to the Virtual Disk Mount Service (vmount2.exe), related to the ConnectPopulatedDiskEx function.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
vendor_vmware·2008-08-29·CVSS 1.9
CVE-2007-5269 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
VMSA-2008-0014: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
I Security Issues a. Setting ActiveX killbit Starting from this release, VMware has set the killbit on its ActiveX controls. Setting the killbit ensures that ActiveX controls cannot run in Internet Explorer (IE), and avoids Microsoft KB article 240797 and the related references on this topic. Security vulnerabilities have been reported for ActiveX controls provided by VMware when run in IE. Under specific circumstances, exploitation of these ActiveX controls might result in denial-of- service or can allow running of arbitrary code when the user browses a malicious Web site or opens a malicious file i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://osvdb.org/43488http://secunia.com/advisories/31707http://secunia.com/advisories/31708http://secunia.com/advisories/31709http://secunia.com/advisories/31710http://securityreason.com/securityalert/3219http://www.eleytt.com/advisories/eleytt_VMWARE1.pdfhttp://www.securityfocus.com/archive/1/482021/100/0/threadedhttp://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/26025http://www.securitytracker.com/id?1020791http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2008/2466http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://osvdb.org/43488http://secunia.com/advisories/31707http://secunia.com/advisories/31708http://secunia.com/advisories/31709http://secunia.com/advisories/31710http://securityreason.com/securityalert/3219http://www.eleytt.com/advisories/eleytt_VMWARE1.pdfhttp://www.securityfocus.com/archive/1/482021/100/0/threadedhttp://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/26025http://www.securitytracker.com/id?1020791http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2008/2466
2007-10-13
Published