CVE-2013-1659
published 2013-02-22CVE-2013-1659: VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not…
PriorityP340high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
1.82%
76.3th percentile
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server_appliance | — | — |
| vmware | vcenter_server_appliance | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server, ESXi and ESX address an NFC Protocol memory corruption and third party library security issues.
vendor_vmware·2013-02-21·CVSS 7.6
CVE-2012-2110 [HIGH] VMware vCenter Server, ESXi and ESX address an NFC Protocol memory corruption and third party library security issues.
VMSA-2013-0003: VMware vCenter Server, ESXi and ESX address an NFC Protocol memory corruption and third party library security issues.
a. VMware vCenter, ESXi and ESX NFC protocol memory corruption vulnerability VMware vCenter Server, ESXi and ESX contain a vulnerability in the handling of the Network File Copy (NFC) protocol. To exploit this vulnerability, an attacker must intercept and modify the NFC traffic between vCenter Server and the client or ESXi/ESX and the client. Exploitation of the issue may lead to code execution. To reduce the likelihood of exploitation, vSphere components should be deployed on an isolated management network VMware would like to thank Alex Chapman of Context Information Security for reporting this issue to us. The Common Vulnerabilities and Exposures projec
VMware
VMware ESX, Workstation, Fusion, and View VMCI privilege escalation vulnerability
vendor_vmware·2013-02-07·CVSS 7.2
CVE-2012-2110 [HIGH] VMware ESX, Workstation, Fusion, and View VMCI privilege escalation vulnerability
VMSA-2013-0002: VMware ESX, Workstation, Fusion, and View VMCI privilege escalation vulnerability
a. VMware VMCI privilege escalation VMware ESX, Workstation, Fusion, and View contain a vulnerability in the handling of control code in vmci.sys. A local malicious user may exploit this vulnerability to manipulate the memory allocation through the Virtual Machine Communication Interface (VMCI) code. This could result in a privilege escalation on Windows-based hosts and on Windows-based Guest Operating Systems. The vulnerability does not allow for privilege escalation from the Guest Operating System to the host (and vice versa). This means that host memory can not be manipulated from the Guest Operating System (and vice versa). Systems that have VMCI disabled are also affected by this issue.
GHSA
GHSA-6232-r5r4-983j: VMware vCenter Server 4
ghsa_unreviewed·2022-05-17
CVE-2013-1659 [HIGH] GHSA-6232-r5r4-983j: VMware vCenter Server 4
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.
No detection rules found.
No writeups or analysis indexed.
2013-02-22
Published