CVE-2013-5972
published 2013-11-18CVE-2013-5972: VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.41%
33.6th percentile
VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation host privilege escalation vulnerability
vendor_vmware·2013-11-14·CVSS 7.9
CVE-2013-3519 [HIGH] VMware Workstation host privilege escalation vulnerability
VMSA-2013-0013: VMware Workstation host privilege escalation vulnerability
a. VMware shared library privilege escalation VMware Workstation and VMware Player contain a vulnerability in the handling of shared libraries. This issue may allow a local malicious user to escalate their privileges to root on the host OS. The vulnerability does not allow for privilege escalation from the Guest Operating System to the host or vice-versa. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2013-5972 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with / Apply Patch VMware Product Workstation Product Version 10.x
VMware
VMware vSphere updates address multiple vulnerabilities
vendor_vmware·2013-10-17·CVSS 7.1
CVE-2013-5970 [HIGH] VMware vSphere updates address multiple vulnerabilities
VMSA-2013-0012: VMware vSphere updates address multiple vulnerabilities
a. VMware ESXi and ESX contain a vulnerability in hostd-vmdb. To exploit this vulnerability, an attacker must intercept and modify the management traffic. Exploitation of the issue may lead to a Denial of Service of the hostd-vmdb service. To reduce the likelihood of exploitation, vSphere components should be deployed on an isolated management network. VMware would like to thank Alex Chapman of Context Information Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2013-5970 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Pro
GHSA
GHSA-m5hv-qvxr-7rrh: VMware Workstation 9
ghsa_unreviewed·2022-05-17
CVE-2013-5972 [HIGH] GHSA-m5hv-qvxr-7rrh: VMware Workstation 9
VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-18
Published