CVE-2012-1515
published 2012-04-02CVE-2012-1515: VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS…
PriorityP432high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
0.82%
53.6th percentile
VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8758-2jw5-f6gw: VMware ESXi 3
ghsa_unreviewed·2022-05-14
CVE-2012-1515 [HIGH] GHSA-8758-2jw5-f6gw: VMware ESXi 3
VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine.
VMware
VMware ESXi and ESX address several security issues
vendor_vmware·2012-03-29·CVSS 8.3
CVE-2011-2482 [HIGH] VMware ESXi and ESX address several security issues
VMSA-2012-0006: VMware ESXi and ESX address several security issues
a. VMware ROM Overwrite Privilege Escalation A flaw in the way port-based I/O is handled allows for modifying Read-Only Memory that belongs to the Virtual DOS Machine. Exploitation of this issue may lead to privilege escalation on Guest Operating Systems that run Windows 2000, Windows XP 32-bit, Windows Server 2003 32-bit or Windows Server 2003 R2 32-bit. VMware would like to thank Derek Soeder of Ridgeway Internet Security, L.L.C. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-1515 this issues. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/52820http://www.securitytracker.com/id?1026875http://www.us-cert.gov/cas/techalerts/TA12-164A.htmlhttp://www.vmware.com/security/advisories/VMSA-2012-0006.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-042https://exchange.xforce.ibmcloud.com/vulnerabilities/74480https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15209https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17110http://www.securityfocus.com/bid/52820http://www.securitytracker.com/id?1026875http://www.us-cert.gov/cas/techalerts/TA12-164A.htmlhttp://www.vmware.com/security/advisories/VMSA-2012-0006.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-042https://exchange.xforce.ibmcloud.com/vulnerabilities/74480https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15209https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17110
2012-04-02
Published