CVE-2012-4897
published 2012-10-05CVE-2012-4897: Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable…
PriorityP418medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.0th percentile
Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | movie_decoder | <= 7.1.2 | — |
| vmware | movie_decoder | — | — |
| vmware | movie_decoder | — | — |
| vmware | movie_decoder | — | — |
| vmware | movie_decoder | — | — |
| vmware | movie_decoder | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Operations, CapacityIQ, and Movie Decoder security updates
vendor_vmware·2012-10-04·CVSS 6.9
CVE-2012-4897 [MEDIUM] VMware vCenter Operations, CapacityIQ, and Movie Decoder security updates
VMSA-2012-0014: VMware vCenter Operations, CapacityIQ, and Movie Decoder security updates
a. VMware Movie Decoder Installer binary planting vulnerability The installer of the VMware Movie Decoder has a binary planting vulnerability. An attacker who can write their malicious executable to the same folder as where the installer of the Movie Decoder is located may be able to run their code when the installation is started. VMware would like to thank Mitja Kolsek of ACROS Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-4897 to this issue. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product Movie Decoder Product Version 7.x Running on Windows Replace with/ Apply Patch Movie D
GHSA
GHSA-553f-j478-v9xg: Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9
ghsa_unreviewed·2022-05-17
CVE-2012-4897 [MEDIUM] GHSA-553f-j478-v9xg: Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9
Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2012-10/0069.htmlhttp://osvdb.org/85957http://www.securityfocus.com/bid/55802http://www.vmware.com/security/advisories/VMSA-2012-0014.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79046http://archives.neohapsis.com/archives/bugtraq/2012-10/0069.htmlhttp://osvdb.org/85957http://www.securityfocus.com/bid/55802http://www.vmware.com/security/advisories/VMSA-2012-0014.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79046
2012-10-05
Published