CVE-2008-3761
published 2008-08-21CVE-2008-3761: hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build…
PriorityP419medium4.9CVSS 2.0
AVLACLAuNCNINAC
EXPLOIT
EPSS
1.00%
58.5th percentile
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | <= 2.5.1 | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | player | <= 2.5.1 | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xcc9-w59f-794q: Unspecified vulnerability in an ioctl in hcmon
ghsa_unreviewed·2022-05-02·CVSS 4.9
CVE-2009-1146 [MEDIUM] GHSA-xcc9-w59f-794q: Unspecified vulnerability in an ioctl in hcmon
Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761.
GHSA
GHSA-cqgj-ggx7-phrm: hcmon
ghsa_unreviewed·2022-05-02
CVE-2008-3761 [MEDIUM] CWE-20 GHSA-cqgj-ggx7-phrm: hcmon
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.
VMware
VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
vendor_vmware·2009-04-03·CVSS 4.6
CVE-2008-3761 [MEDIUM] VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
VMSA-2009-0005: VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
a. Denial of service guest to host vulnerability in a virtual device A vulnerability in a guest virtual device driver, could allow a guest operating system to crash the host and consequently any virtual machines on that host. VMware would like to thank Andrew Honig of the Department of Defense for reporting this issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-4916 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product =============
No detection rules found.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2009/000054.htmlhttp://seclists.org/fulldisclosure/2009/Apr/0036.htmlhttp://securityreason.com/securityalert/4177http://www.orange-bat.com/adv/2008/adv.08.17.txthttp://www.securityfocus.com/bid/30737http://www.securityfocus.com/bid/34373http://www.securitytracker.com/id?1020715http://www.vmware.com/security/advisories/VMSA-2009-0005.htmlhttp://www.vupen.com/english/advisories/2009/0944https://exchange.xforce.ibmcloud.com/vulnerabilities/44539https://www.exploit-db.com/exploits/6262http://lists.vmware.com/pipermail/security-announce/2009/000054.htmlhttp://seclists.org/fulldisclosure/2009/Apr/0036.htmlhttp://securityreason.com/securityalert/4177http://www.orange-bat.com/adv/2008/adv.08.17.txthttp://www.securityfocus.com/bid/30737http://www.securityfocus.com/bid/34373http://www.securitytracker.com/id?1020715http://www.vmware.com/security/advisories/VMSA-2009-0005.htmlhttp://www.vupen.com/english/advisories/2009/0944https://exchange.xforce.ibmcloud.com/vulnerabilities/44539https://www.exploit-db.com/exploits/6262
2008-08-21
Published