CVE-2009-3732
published 2010-04-12CVE-2009-3732: Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via…
PriorityP265critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
16.20%
96.6th percentile
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | >= 2.5.0 < 2.5.4 | 2.5.4 |
| vmware | player | — | — |
| vmware | player | >= 2.5.0 < 2.5.4 | 2.5.4 |
| vmware | server | 2.0.0 – 2.0.2 | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 6.5.0 < 6.5.4 | 6.5.4 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor process execution of vmware-vmrc.exe with command-line arguments containing format string specifiers (e.g., %x, %n, %s) in the -M (MOID) or -h (HOST) parameters, which are the vulnerable injection points. ↗
- →Detect instantiation or scripting of the VMware Remote Console ActiveX control by its CLSID (B94C2238-346E-4C5E-9B36-8CC627F35574) in web pages or HTML, particularly when the connect() method is called with format string characters in the MOID or HOST arguments. ↗
- →Alert on error dialog strings from vmware-vmrc.exe that echo back user-supplied format specifiers, indicating successful format string injection: 'Error opening the remote virtual machine HOST\MOID'. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
vendor_vmware·2010-04-09·CVSS 8.5
CVE-2009-1564 [HIGH] VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
VMSA-2010-0007: VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
a. Windows-based VMware Tools Unsafe Library Loading vulnerability A vulnerability in the way VMware libraries are referenced allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to lure the user that is logged on a Windows Guest Operating System to click on the attacker's file on a network share. This file could be in any file format. The attacker will need to have the ability to host their malicious files on a network share. VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS Security ( http://www.across
GHSA
GHSA-mw96-29xv-5ppf: Format string vulnerability in vmware-vmrc
ghsa_unreviewed·2022-05-02
CVE-2009-3732 [HIGH] CWE-134 GHSA-mw96-29xv-5ppf: Format string vulnerability in vmware-vmrc
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://secunia.com/advisories/39110http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.vmware.com/security/advisories/VMSA-2010-0007.htmlhttp://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://secunia.com/advisories/39110http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.vmware.com/security/advisories/VMSA-2010-0007.html
2010-04-12
Published