CVE-2012-1509
published 2012-03-16CVE-2012-1509: Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.44%
35.4th percentile
Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | view | <= 4.6.0 | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x923-j6cr-r4gr: Buffer overflow in the XPDM display driver in VMware View before 4
ghsa_unreviewed·2022-05-17
CVE-2012-1509 [HIGH] CWE-119 GHSA-x923-j6cr-r4gr: Buffer overflow in the XPDM display driver in VMware View before 4
Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
VMware
VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
vendor_vmware·2012-03-15·CVSS 7.2
CVE-2010-0405 [HIGH] VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
VMSA-2012-0005: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
a. VMware Tools Display Driver Privilege Escalation The VMware XPDM and WDDM display drivers contain buffer overflow vulnerabilities and the XPDM display driver does not properly check for NULL pointers. Exploitation of these issues may lead to local privilege escalation on Windows-based Guest Operating Systems. VMware would like to thank Tarjei Mandt for reporting theses issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2012-1509 (XPDM buffer overrun), CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null pointer dereference) to these issues. Note: CVE-2012-1509 do
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2012-03/0071.htmlhttp://osvdb.org/80116http://secunia.com/advisories/48379http://www.securityfocus.com/bid/52524http://www.securitytracker.com/id?1026814http://www.vmware.com/security/advisories/VMSA-2012-0004.htmlhttp://www.vmware.com/security/advisories/VMSA-2012-0005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74096https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17151http://archives.neohapsis.com/archives/bugtraq/2012-03/0071.htmlhttp://osvdb.org/80116http://secunia.com/advisories/48379http://www.securityfocus.com/bid/52524http://www.securitytracker.com/id?1026814http://www.vmware.com/security/advisories/VMSA-2012-0004.htmlhttp://www.vmware.com/security/advisories/VMSA-2012-0005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74096https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17151
2012-03-16
Published