CVE-2011-3868
published 2011-10-07CVE-2011-3868: Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote…
PriorityP349critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.77%
92.3th percentile
Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7jrj-rw38-cw85: Buffer overflow in VMware Workstation 7
ghsa_unreviewed·2022-05-14
CVE-2011-3868 [HIGH] CWE-119 GHSA-7jrj-rw38-cw85: Buffer overflow in VMware Workstation 7
Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.
VMware
VMware hosted products address remote code execution vulnerability
vendor_vmware·2011-10-04·CVSS 9.3
CVE-2011-3868 [CRITICAL] VMware hosted products address remote code execution vulnerability
VMSA-2011-0011: VMware hosted products address remote code execution vulnerability
a. UDF file system import remote code execution A buffer overflow vulnerability is present in the way UDF file systems are handled. This issue could allow for code execution if a user installs from a malicious ISO image that was specially crafted by an attacker. VMware would like to thank an anonymous contributor working with the SecuriTeam Secure Disclosure program for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2011-3868 to the issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ==
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/76060http://secunia.com/advisories/46241http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/archive/1/520005/100/0/threadedhttp://www.securityfocus.com/bid/49942http://www.securitytracker.com/id?1026139http://www.vmware.com/security/advisories/VMSA-2011-0011.htmlhttp://osvdb.org/76060http://secunia.com/advisories/46241http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/archive/1/520005/100/0/threadedhttp://www.securityfocus.com/bid/49942http://www.securitytracker.com/id?1026139http://www.vmware.com/security/advisories/VMSA-2011-0011.html
2011-10-07
Published