CVE-2013-5973
published 2013-12-23CVE-2013-5973: VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource…
PriorityP418medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.35%
27.9th percentile
VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi and ESX unauthorized file access through vCenter Server and ESX
vendor_vmware·2013-12-22·CVSS 4.4
CVE-2013-5973 [MEDIUM] VMware ESXi and ESX unauthorized file access through vCenter Server and ESX
VMSA-2013-0016: VMware ESXi and ESX unauthorized file access through vCenter Server and ESX
a. VMware ESXi and ESX unauthorized file access through vCenter Server and ESX VMware ESXi and ESX contain a vulnerability in the handling of certain Virtual Machine file descriptors. This issue may allow an unprivileged vCenter Server user with the privilege “Add Existing Disk" to obtain read and write access to arbitrary files on ESXi or ESX. On ESX, an unprivileged local user may obtain read and write access to arbitrary files. Modifying certain files may allow for code execution after a host reboot. Unpriviledged vCenter Server users or groups that are assigned the predefined role "Virtual Machine Power User" or "Resource Pool Administrator" have the privilege "Add Existing Disk". The issue can
GHSA
GHSA-gw29-qp68-r97c: VMware ESXi 4
ghsa_unreviewed·2022-05-14
CVE-2013-5973 [MEDIUM] GHSA-gw29-qp68-r97c: VMware ESXi 4
VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://jvn.jp/en/jp/JVN13154935/index.htmlhttp://jvndb.jvn.jp/en/contents/2013/JVNDB-2013-000123.htmlhttp://osvdb.org/101387http://www.securityfocus.com/archive/1/530482/100/0/threadedhttp://www.securityfocus.com/bid/64491http://www.securitytracker.com/id/1029529http://www.vmware.com/security/advisories/VMSA-2013-0016.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/89938http://jvn.jp/en/jp/JVN13154935/index.htmlhttp://jvndb.jvn.jp/en/contents/2013/JVNDB-2013-000123.htmlhttp://osvdb.org/101387http://www.securityfocus.com/archive/1/530482/100/0/threadedhttp://www.securityfocus.com/bid/64491http://www.securitytracker.com/id/1029529http://www.vmware.com/security/advisories/VMSA-2013-0016.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/89938
2013-12-23
Published