CVE-2012-1518
published 2012-04-17CVE-2012-1518: VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through…
PriorityP434high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
1.72%
74.9th percentile
VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted products and ESXi/ESX patches address privilege escalation
vendor_vmware·2012-04-12·CVSS 8.3
CVE-2012-1518 [HIGH] VMware hosted products and ESXi/ESX patches address privilege escalation
VMSA-2012-0007: VMware hosted products and ESXi/ESX patches address privilege escalation
a. VMware Tools Incorrect Folder Permissions Privilege Escalation The access control list of the VMware Tools folder is incorrectly set. Exploitation of this issue may lead to local privilege escalation on Windows-based Guest Operating Systems. VMware would like to thank Tavis Ormandy for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-1518 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch * VMware Product vCenter Product Version any Running on Windows Replace wi
GHSA
GHSA-4vv7-8gg7-f95h: VMware Workstation 8
ghsa_unreviewed·2022-05-14
CVE-2012-1518 [HIGH] GHSA-4vv7-8gg7-f95h: VMware Workstation 8
VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/81163http://secunia.com/advisories/48782http://www.securityfocus.com/bid/53006http://www.securitytracker.com/id?1026922http://www.securitytracker.com/id?1026923http://www.vmware.com/security/advisories/VMSA-2012-0007.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16745http://osvdb.org/81163http://secunia.com/advisories/48782http://www.securityfocus.com/bid/53006http://www.securitytracker.com/id?1026922http://www.securitytracker.com/id?1026923http://www.vmware.com/security/advisories/VMSA-2012-0007.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16745
2012-04-17
Published