CVE-2009-2267
published 2009-11-02CVE-2009-2267: VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server…
PriorityP277medium6.9CVSS 2.0
AVLACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
1.75%
75.4th percentile
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets Virtual-8086 mode privilege escalation on guest OS by specifying a crafted value for the cs register during a page fault (#PF) exception — monitor guest OS processes for unexpected ring0/privilege escalation originating from V86 mode. ↗
- →Exploit is classified as a Linux local Ring0 privilege escalation via VMware Virtual 8086 mode — look for local privilege escalation events on Linux guest OSes running inside affected VMware products. ↗
- →Vulnerability only affects the guest OS, not the host system — scope detection efforts to guest OS privilege escalation monitoring rather than host-level indicators. ↗
- ·Vulnerability is only exploitable when Virtual-8086 mode is in use on the guest OS — environments not using V86 mode are not at risk. ↗
- ·Fixed builds are: Workstation/Player/ACE 6.5.3/2.5.3 build 185404, Server 1.0.10 build 203137 / 2.0.2 build 203138, Fusion 2.0.6 build 196839, ESXi 4.0 ESXi400-200909401-BG, ESXi 3.5 ESXe350-200910401-I-SG, ESX 4.0 ESX400-200909401-BG, ESX 3.5 ESX350-200910401-SG, ESX 3.0.3 ESX303-200910401-BG, ESX 2.5.5 Patch 15. ↗
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vulncheck6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3rg-38gc-7x9q: VMware Workstation 6
ghsa_unreviewed·2022-05-02
CVE-2009-2267 [MEDIUM] GHSA-r3rg-38gc-7x9q: VMware Workstation 6
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.
VulnCheck
VMware Products Guest Privilege Escalation Vulnerability
vulncheck·2009·CVSS 6.9
CVE-2009-2267 [MEDIUM] VMware Products Guest Privilege Escalation Vulnerability
VMware Products Guest Privilege Escalation Vulnerability
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.
Affected: VMware ace
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Ex
VMware
VMware hosted products and ESX patches resolve two security issues
vendor_vmware·2009-10-27·CVSS 6.9
CVE-2009-2267 [MEDIUM] VMware hosted products and ESX patches resolve two security issues
VMSA-2009-0015: VMware hosted products and ESX patches resolve two security issues
a. Mishandled exception on page faults An improper setting of the exception code on page faults may allow for local privilege escalation on the guest operating system. This vulnerability does not affect the host system. VMware would like to thank Tavis Ormandy and Julien Tinnes of the Google Security Team for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-2267 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= VirtualCen
No detection rules found.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2009/000069.htmlhttp://secunia.com/advisories/37172http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securitytracker.com/id?1023082http://securitytracker.com/id?1023083http://www.securityfocus.com/archive/1/507523/100/0/threadedhttp://www.securityfocus.com/archive/1/507539/100/0/threadedhttp://www.securityfocus.com/bid/36841http://www.vmware.com/security/advisories/VMSA-2009-0015.htmlhttp://www.vupen.com/english/advisories/2009/3062https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8473http://lists.vmware.com/pipermail/security-announce/2009/000069.htmlhttp://secunia.com/advisories/37172http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securitytracker.com/id?1023082http://securitytracker.com/id?1023083http://www.securityfocus.com/archive/1/507523/100/0/threadedhttp://www.securityfocus.com/archive/1/507539/100/0/threadedhttp://www.securityfocus.com/bid/36841http://www.vmware.com/security/advisories/VMSA-2009-0015.htmlhttp://www.vupen.com/english/advisories/2009/3062https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8473
2009-11-02
Published
Exploited in the wild