CVE-2013-3519
published 2013-12-04CVE-2013-3519: lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware…
PriorityP430high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
0.51%
39.9th percentile
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation, Fusion, ESXi and ESX patches address a guest privilege escalation
vendor_vmware·2013-12-03·CVSS 7.9
CVE-2013-0791 [HIGH] VMware Workstation, Fusion, ESXi and ESX patches address a guest privilege escalation
VMSA-2013-0014: VMware Workstation, Fusion, ESXi and ESX patches address a guest privilege escalation
a. VMware LGTOSYNC privilege escalation. VMware ESX, Workstation and Fusion contain a vulnerability in the handling of control code in lgtosync.sys. A local malicious user may exploit this vulnerability to manipulate the memory allocation. This could result in a privilege escalation on 32-bit Guest Operating Systems running Windows 2000 Server, Windows XP or Windows 2003 Server on ESXi and ESX; or Windows XP on Workstation and Fusion. The vulnerability does not allow for privilege escalation from the Guest Operating System to the host. This means that host memory can not be manipulated from the Guest Operating System. VMware would like to thank Derek Soeder of Cylance, Inc. for reporting
VMware
VMware Workstation host privilege escalation vulnerability
vendor_vmware·2013-11-14·CVSS 7.9
CVE-2013-3519 [HIGH] VMware Workstation host privilege escalation vulnerability
VMSA-2013-0013: VMware Workstation host privilege escalation vulnerability
a. VMware shared library privilege escalation VMware Workstation and VMware Player contain a vulnerability in the handling of shared libraries. This issue may allow a local malicious user to escalate their privileges to root on the host OS. The vulnerability does not allow for privilege escalation from the Guest Operating System to the host or vice-versa. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2013-5972 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with / Apply Patch VMware Product Workstation Product Version 10.x
GHSA
GHSA-8xv9-xcpm-7f4g: lgtosync
ghsa_unreviewed·2022-05-17
CVE-2013-3519 [HIGH] GHSA-8xv9-xcpm-7f4g: lgtosync
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-12-04
Published