CVE-2009-3707
published 2009-10-16CVE-2009-3707: VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
11.11%
95.5th percentile
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
vendor_vmware·2010-04-09·CVSS 8.5
CVE-2009-1564 [HIGH] VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
VMSA-2010-0007: VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
a. Windows-based VMware Tools Unsafe Library Loading vulnerability A vulnerability in the way VMware libraries are referenced allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to lure the user that is logged on a Windows Guest Operating System to click on the attacker's file on a network share. This file could be in any file format. The attacker will need to have the ability to host their malicious files on a network share. VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS Security ( http://www.across
GHSA
GHSA-47pm-rhm6-w3xc: VMware Authentication Daemon 1
ghsa_unreviewed·2022-05-02
CVE-2009-3707 [MEDIUM] CWE-134 GHSA-47pm-rhm6-w3xc: VMware Authentication Daemon 1
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-8jq2-g365-87pp: VMware Authentication Daemon 1
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-4811 [MEDIUM] CWE-134 GHSA-8jq2-g365-87pp: VMware Authentication Daemon 1
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\x90 sequence in the USER and PASS commands, a related issue to CVE-2009-3707. NOTE: some of these details are obtained from third party information.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://secunia.com/advisories/36988http://secunia.com/advisories/39206http://secunia.com/advisories/39215http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securitytracker.com/id?1022997http://www.securityfocus.com/bid/36630http://www.shinnai.net/exploits/abFwcLOuFqmD20yqhYpQ.txthttp://www.shinnai.net/index.php?mod=02_Forum&group=02_Bugs_and_Exploits&argument=01_Remote&topic=1254924405.ff.phphttp://www.shinnai.net/xplits/TXT_JtYUv6C6j5b6Bw6iIkF4.htmlhttp://www.vmware.com/security/advisories/VMSA-2010-0007.htmlhttp://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://secunia.com/advisories/36988http://secunia.com/advisories/39206http://secunia.com/advisories/39215http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securitytracker.com/id?1022997http://www.securityfocus.com/bid/36630http://www.shinnai.net/exploits/abFwcLOuFqmD20yqhYpQ.txthttp://www.shinnai.net/index.php?mod=02_Forum&group=02_Bugs_and_Exploits&argument=01_Remote&topic=1254924405.ff.phphttp://www.shinnai.net/xplits/TXT_JtYUv6C6j5b6Bw6iIkF4.htmlhttp://www.vmware.com/security/advisories/VMSA-2010-0007.html
2009-10-16
Published