CVE-2011-1787
published 2011-06-06CVE-2011-1787: Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware…
PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.24%
15.1th percentile
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | open-vm-tools | < open-vm-tools 2:8.4.2+2011.08.21-471295-1 (bookworm) | open-vm-tools 2:8.4.2+2011.08.21-471295-1 (bookworm) |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | open-vm-tools | >= 0 < 2:8.4.2+2011.08.21-471295-1 | 2:8.4.2+2011.08.21-471295-1 |
| vmware | open-vm-tools | >= 0 < 2:8.4.2+2011.08.21-471295-1 | 2:8.4.2+2011.08.21-471295-1 |
| vmware | open-vm-tools | >= 0 < 2:8.4.2+2011.08.21-471295-1 | 2:8.4.2+2011.08.21-471295-1 |
| vmware | open-vm-tools | >= 0 < 2:8.4.2+2011.08.21-471295-1 | 2:8.4.2+2011.08.21-471295-1 |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| vmware | workstation | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues
vendor_vmware·2011-06-02·CVSS 7.8
CVE-2009-3080 [HIGH] VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues
VMSA-2011-0009: VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues
a. VMware vmkernel third party e1000(e) Driver Packet Filter Bypass There is an issue in the e1000(e) Linux driver for Intel PRO/1000 adapters that allows a remote attacker to bypass packet filters. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-4536 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= vCenter Product Version ======= any Running on ======= Windows Replace with/ Apply Patch ===
Debian
CVE-2011-1787: open-vm-tools - Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VM...
vendor_debian·2011·CVSS 6.9
CVE-2011-1787 [MEDIUM] CVE-2011-1787: open-vm-tools - Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VM...
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.
Scope: local
bookworm: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
bullseye: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
forky: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
sid: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
trixie: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
GHSA
GHSA-cm43-w9vf-5r6r: Race condition in mount
ghsa_unreviewed·2022-05-17
CVE-2011-1787 [MEDIUM] CWE-362 GHSA-cm43-w9vf-5r6r: Race condition in mount
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.
OSV
CVE-2011-1787: Race condition in mount
osv·2011-06-06·CVSS 6.9
CVE-2011-1787 [MEDIUM] CVE-2011-1787: Race condition in mount
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/44840http://secunia.com/advisories/44904http://www.securityfocus.com/bid/48098http://www.securitytracker.com/id?1025601http://www.vmware.com/security/advisories/VMSA-2011-0009.htmlhttps://hermes.opensuse.org/messages/8711677http://secunia.com/advisories/44840http://secunia.com/advisories/44904http://www.securityfocus.com/bid/48098http://www.securitytracker.com/id?1025601http://www.vmware.com/security/advisories/VMSA-2011-0009.htmlhttps://hermes.opensuse.org/messages/8711677
2011-06-06
Published