CVE-2010-3277
published 2010-09-28CVE-2010-3277: The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.30%
22.5th percentile
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-38hp-c2qq-q6vh: The installer in VMware Workstation 7
ghsa_unreviewed·2022-05-17
CVE-2010-3277 [LOW] GHSA-38hp-c2qq-q6vh: The installer in VMware Workstation 7
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.
VMware
VMware Workstation, Player, and ACE address several security issues.
vendor_vmware·2010-09-23·CVSS 2.1
CVE-2010-0205 [LOW] VMware Workstation, Player, and ACE address several security issues.
VMSA-2010-0014: VMware Workstation, Player, and ACE address several security issues.
a. VMware Workstation and Player installer security issue The Workstation 7.x and Player 3.x installers will load an index.htm file located in the current working directory on which Workstation 7.x or Player 3.x is being installed. This may allow an attacker to display a malicious file if they manage to get their file onto the system prior to installation. The issue can only be exploited at the time that Workstation 7.x or Player 3.x is being installed. Installed versions of Workstation and Player are not affected. The security issue is no longer present in the installer of the new versions of Workstation 7.x and Player 3.x (see table below for the version numbers). The Common Vulnerabilities and Exposure
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://secunia.com/advisories/41574http://securitytracker.com/id?1024481http://www.vmware.com/security/advisories/VMSA-2010-0014.htmlhttp://www.vupen.com/english/advisories/2010/2491http://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://secunia.com/advisories/41574http://securitytracker.com/id?1024481http://www.vmware.com/security/advisories/VMSA-2010-0014.htmlhttp://www.vupen.com/english/advisories/2010/2491
2010-09-28
Published