CVE-2012-5458
published 2012-11-14CVE-2012-5458: VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS…
PriorityP431high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
0.70%
49.5th percentile
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Hosted Products and OVF Tool address security issues
vendor_vmware·2012-11-08·CVSS 8.3
CVE-2012-3569 [HIGH] VMware Hosted Products and OVF Tool address security issues
VMSA-2012-0015: VMware Hosted Products and OVF Tool address security issues
a. VMware Workstation and Player Weak permissions on process threads vulnerability. Certain processes when created have weak security permissions assigned. It is possible to commandeer these process threads, which could result in Elevation of Privilege in the context of the host. VMware would like to thank Derek Soeder of Cylance, Inc. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5458 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product vCenter Product Vers
GHSA
GHSA-f9mp-7f7v-39g9: VMware Workstation 8
ghsa_unreviewed·2022-05-17
CVE-2012-5458 [HIGH] GHSA-f9mp-7f7v-39g9: VMware Workstation 8
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/87118http://www.securityfocus.com/bid/56469http://www.vmware.com/security/advisories/VMSA-2012-0015.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79924http://osvdb.org/87118http://www.securityfocus.com/bid/56469http://www.vmware.com/security/advisories/VMSA-2012-0015.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79924
2012-11-14
Published