CVE-2010-4295

CWE-362Race Condition3 documents3 sources
Severity
6.9MEDIUM
EPSS
0.1%
top 82.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 14

Description

Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via vectors involving temporary files.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages4 packages

NVDvmware/fusion3.1, 3.1.1, 3.1.2+2
NVDvmware/player3.1, 3.1.1, 3.1.2+2
NVDvmware/server2.0.2
NVDvmware/workstation5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-fmhg-h6vw-qwgj: Race condition in the mounting process in vmware-mount in VMware Workstation 72022-05-14
CVEList
CVE-2010-4295: Race condition in the mounting process in vmware-mount in VMware Workstation 72010-12-06