CVE-2008-4915
published 2008-11-10CVE-2008-4915: The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.0th percentile
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | 1.0 – 1.0.7 | — |
| vmware | ace | 2.0 – 2.0.5 | — |
| vmware | esx | 2.5.4 – 3.5 | — |
| vmware | esxi | — | — |
| vmware | player | 1.0.0 – 1.0.8 | — |
| vmware | player | 2.0 – 2.0.5 | — |
| vmware | server | 1.0 – 1.0.7 | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | 5.5 – 5.5.8 | — |
| vmware | workstation | 6.0 – 6.0.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Hosted products and patches for ESX and ESXi resolve two security issues
vendor_vmware·2008-11-06·CVSS 6.9
CVE-2008-4281 [MEDIUM] VMware Hosted products and patches for ESX and ESXi resolve two security issues
VMSA-2008-0018: VMware Hosted products and patches for ESX and ESXi resolve two security issues
a. A privilege escalation on 32-bit and 64-bit guest operating systems VMware products emulate hardware functions and create the possibility to run guest operating systems. A flaw in the CPU hardware emulation might allow the virtual CPU to incorrectly handle the Trap flag. Exploitation of this flaw might lead to a privilege escalation on guest operating systems. An attacker needs a user account on the guest operating system and have the ability to run applications. VMware would like to thank Derek Soeder for discovering this issue and working with us on its remediation. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-4915 to this issue. The follo
GHSA
GHSA-pj5p-qr67-x54j: The CPU hardware emulation in VMware Workstation 6
ghsa_unreviewed·2022-05-14
CVE-2008-4915 [MEDIUM] GHSA-pj5p-qr67-x54j: The CPU hardware emulation in VMware Workstation 6
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2008/000042.htmlhttp://secunia.com/advisories/32612http://secunia.com/advisories/32624http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/archive/1/498138/100/0/threadedhttp://www.securityfocus.com/bid/32168http://www.securitytracker.com/id?1021154http://www.vmware.com/security/advisories/VMSA-2008-0018.htmlhttp://www.vupen.com/english/advisories/2008/3052https://exchange.xforce.ibmcloud.com/vulnerabilities/46415https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6309http://lists.vmware.com/pipermail/security-announce/2008/000042.htmlhttp://secunia.com/advisories/32612http://secunia.com/advisories/32624http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/archive/1/498138/100/0/threadedhttp://www.securityfocus.com/bid/32168http://www.securitytracker.com/id?1021154http://www.vmware.com/security/advisories/VMSA-2008-0018.htmlhttp://www.vupen.com/english/advisories/2008/3052https://exchange.xforce.ibmcloud.com/vulnerabilities/46415https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6309
2008-11-10
Published