cbcvebase.
CVE-2009-2267
published 2009-11-02

CVE-2009-2267: VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server…

PriorityP277medium6.9CVSS 2.0
AVLACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
1.75%
75.4th percentile
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
vmwareace
vmwareace
vmwareace
vmwareesx
vmwareesx
vmwareesx
vmwareesx
vmwareesxi
vmwareesxi
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwareplayer
vmwareplayer
vmwareplayer
vmwareserver
vmwareserver
vmwareserver
vmwareserver
vmwareserver
vmwareserver
vmwareserver

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/10207.tar.gz
  • Exploit targets Virtual-8086 mode privilege escalation on guest OS by specifying a crafted value for the cs register during a page fault (#PF) exception — monitor guest OS processes for unexpected ring0/privilege escalation originating from V86 mode.
  • Exploit is classified as a Linux local Ring0 privilege escalation via VMware Virtual 8086 mode — look for local privilege escalation events on Linux guest OSes running inside affected VMware products.
  • Vulnerability only affects the guest OS, not the host system — scope detection efforts to guest OS privilege escalation monitoring rather than host-level indicators.
  • ·Vulnerability is only exploitable when Virtual-8086 mode is in use on the guest OS — environments not using V86 mode are not at risk.
  • ·Fixed builds are: Workstation/Player/ACE 6.5.3/2.5.3 build 185404, Server 1.0.10 build 203137 / 2.0.2 build 203138, Fusion 2.0.6 build 196839, ESXi 4.0 ESXi400-200909401-BG, ESXi 3.5 ESXe350-200910401-I-SG, ESX 4.0 ESX400-200909401-BG, ESX 3.5 ESX350-200910401-SG, ESX 3.0.3 ESX303-200910401-BG, ESX 2.5.5 Patch 15.

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vulncheck6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.