CVE-2010-1139
published 2010-04-12CVE-2010-1139: Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.33%
25.5th percentile
Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vix_api | — | — |
| vmware | vix_api | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
vendor_vmware·2010-04-09·CVSS 8.5
CVE-2009-1564 [HIGH] VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
VMSA-2010-0007: VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
a. Windows-based VMware Tools Unsafe Library Loading vulnerability A vulnerability in the way VMware libraries are referenced allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to lure the user that is logged on a Windows Guest Operating System to click on the attacker's file on a network share. This file could be in any file format. The attacker will need to have the ability to host their malicious files on a network share. VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS Security ( http://www.across
GHSA
GHSA-3jcj-m65j-r72c: Format string vulnerability in vmrun in VMware VIX API 1
ghsa_unreviewed·2022-05-02
CVE-2010-1139 [HIGH] CWE-134 GHSA-3jcj-m65j-r72c: Format string vulnerability in vmrun in VMware VIX API 1
Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://osvdb.org/63606http://secunia.com/advisories/39201http://secunia.com/advisories/39206http://secunia.com/advisories/39215http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/bid/39407http://www.securitytracker.com/id?1023835http://www.vmware.com/security/advisories/VMSA-2010-0007.htmlhttp://archives.neohapsis.com/archives/bugtraq/2010-04/0077.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000090.htmlhttp://osvdb.org/63606http://secunia.com/advisories/39201http://secunia.com/advisories/39206http://secunia.com/advisories/39215http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/bid/39407http://www.securitytracker.com/id?1023835http://www.vmware.com/security/advisories/VMSA-2010-0007.html
2010-04-12
Published