CVE-2011-1789
published 2011-05-09CVE-2011-1789: The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.90%
77.3th percentile
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software distribution via a Trojan horse installer.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | vcenter | — | — |
| vmware | vcenter | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server and vSphere Client security vulnerabilities
vendor_vmware·2011-05-05·CVSS 4.3
CVE-2011-0426 [MEDIUM] VMware vCenter Server and vSphere Client security vulnerabilities
VMSA-2011-0008: VMware vCenter Server and vSphere Client security vulnerabilities
a. vCenter Server Directory Traversal vulnerability A directory traversal vulnerability allows an attacker to remotely retrieve files from vCenter Server without authentication. In order to exploit this vulnerability, the attacker will need to have access to the network on which the vCenter Server host resides. In case vCenter Server is installed on Windows 2008 or Windows 2008 R2, the security vulnerability is not present. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2011-0426 to this issue. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= vCenter Product Version ====
GHSA
GHSA-3qx7-92qm-xvhr: The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4
ghsa_unreviewed·2022-05-17
CVE-2011-1789 [MEDIUM] GHSA-3qx7-92qm-xvhr: The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software distribution via a Trojan horse installer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2011/000137.htmlhttp://securitytracker.com/id?1025502http://www.vmware.com/security/advisories/VMSA-2011-0008.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000137.htmlhttp://securitytracker.com/id?1025502http://www.vmware.com/security/advisories/VMSA-2011-0008.html
2011-05-09
Published