CVE-2012-5459
published 2012-11-14CVE-2012-5459: Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS…
PriorityP429high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
0.61%
45.4th percentile
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Hosted Products and OVF Tool address security issues
vendor_vmware·2012-11-08·CVSS 8.3
CVE-2012-3569 [HIGH] VMware Hosted Products and OVF Tool address security issues
VMSA-2012-0015: VMware Hosted Products and OVF Tool address security issues
a. VMware Workstation and Player Weak permissions on process threads vulnerability. Certain processes when created have weak security permissions assigned. It is possible to commandeer these process threads, which could result in Elevation of Privilege in the context of the host. VMware would like to thank Derek Soeder of Cylance, Inc. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5458 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product vCenter Product Vers
GHSA
GHSA-4g79-8pmr-hjx2: Untrusted search path vulnerability in VMware Workstation 8
ghsa_unreviewed·2022-05-17
CVE-2012-5459 [HIGH] GHSA-4g79-8pmr-hjx2: Untrusted search path vulnerability in VMware Workstation 8
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/87119http://www.securityfocus.com/bid/56470http://www.vmware.com/security/advisories/VMSA-2012-0015.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79923http://osvdb.org/87119http://www.securityfocus.com/bid/56470http://www.vmware.com/security/advisories/VMSA-2012-0015.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79923
2012-11-14
Published