CVE-2008-1362
published 2008-03-20CVE-2008-1362: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x…
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.36%
28.2th percentile
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecurely created named pipe," a different vulnerability than CVE-2008-1361.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line
vendor_vmware·2008-03-17·CVSS 6.9
CVE-2006-2937 [MEDIUM] Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line
VMSA-2008-0005: Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line
a. Host to guest shared folder (HGFS) traversal vulnerability On Windows hosts, if you have configured a VMware host to guest shared folder (HGFS), it is possible for a program running in the guest to gain access to the host's file system and create or modify executable files in sensitive locations. NOTE: VMware Server is not affected because it doesn't use host to guest shared folders. No versions of ESX Server, including ESX Server 3i, are affected by this vulnerability. Because ESX Server is based on a bare-metal hypervisor architecture and not a hosted architecture, and it doesn't include any shared folder abilities. Fusion and Linux based hosted product
GHSA
GHSA-3wg9-7hfj-6cp9: VMware Workstation 6
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-1362 [MEDIUM] GHSA-3wg9-7hfj-6cp9: VMware Workstation 6
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecurely created named pipe," a different vulnerability than CVE-2008-1361.
GHSA
GHSA-gv98-9r75-xrjg: VMware Workstation 6
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2008-1361 [HIGH] GHSA-gv98-9r75-xrjg: VMware Workstation 6
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation that causes the authd process to connect to an arbitrary named pipe, a different vulnerability than CVE-2008-1362.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2008/000008.htmlhttp://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securityreason.com/securityalert/3755http://securitytracker.com/id?1019621http://www.securityfocus.com/archive/1/489739/100/0/threadedhttp://www.securityfocus.com/bid/28276http://www.vmware.com/security/advisories/VMSA-2008-0005.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2008/0905/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41259http://lists.vmware.com/pipermail/security-announce/2008/000008.htmlhttp://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securityreason.com/securityalert/3755http://securitytracker.com/id?1019621http://www.securityfocus.com/archive/1/489739/100/0/threadedhttp://www.securityfocus.com/bid/28276http://www.vmware.com/security/advisories/VMSA-2008-0005.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2008/0905/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41259
2008-03-20
Published