cbcvebase.
CVE-2013-5973
published 2013-12-23

CVE-2013-5973: VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource…

PriorityP418medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.35%
27.9th percentile
VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.

Affected

8 ranges
VendorProductVersion rangeFixed in
vmwareesx
vmwareesx
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarevcenter_server
vmwarevmware_esxi
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.