cbcvebase.
CVE-2008-0923
published 2008-02-26

CVE-2008-0923: Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows…

PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.49%
39.1th percentile
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.

Affected

17 ranges
VendorProductVersion rangeFixed in
vmwareace
vmwareace
vmwareace
vmwareace
vmwareace
vmwareplayer
vmwarevmware_fusion
vmwarevmware_player
vmwarevmware_player
vmwarevmware_player
vmwarevmware_workstation
vmwarevmware_workstation
vmwarevmware_workstation
vmwareworkstation
vmwareworkstation
vmwareworkstation
vmwareworkstation
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.