CVE-2014-3793
published 2014-05-31CVE-2014-3793: VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a…
PriorityP422medium5.8CVSS 2.0
AVAACLAuNCPIPAP
EPSS
1.15%
63.5th percentile
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-75q2-28c3-jc72: VMware Tools in VMware Workstation 10
ghsa_unreviewed·2022-05-14
CVE-2014-3793 [MEDIUM] GHSA-75q2-28c3-jc72: VMware Tools in VMware Workstation 10
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.
VMware
VMware Workstation, Player, Fusion, and ESXi patches address a guest privilege escalation
vendor_vmware·2014-05-29·CVSS 5.8
CVE-2014-3793 [MEDIUM] VMware Workstation, Player, Fusion, and ESXi patches address a guest privilege escalation
VMSA-2014-0005: VMware Workstation, Player, Fusion, and ESXi patches address a guest privilege escalation
a. Guest privilege escalation in VMware Tools A kernel NULL dereference vulnerability was found in VMware Tools running on Microsoft Windows 8.1. Successful exploitation of this issue could lead to an escalation of privilege in the guest operating system. VMware would like to thank Tavis Ormandy from the Google Security Team for reporting this issue to us. The vulnerability does not allow for privilege escalation from the Guest Operating System to the host. This means that host memory can not be manipulated from the Guest Operating System. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3793 to this issue. Column 4 of the following table
No detection rules found.
Nuclei
HTTP File Server <2.3c - Remote Command Execution
nuclei·CVSS 9.8
CVE-2014-6287 [CRITICAL] HTTP File Server <2.3c - Remote Command Execution
HTTP File Server =2.3c) to mitigate this vulnerability.
reference:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6287
- http://www.kb.cert.org/vuls/id/251276
- http://packetstormsecurity.com/files/128243/HttpFileServer-2.3.x-Remote-Command-Execution.html
- https://github.com/rapid7/metasploit-framework/pull/3793
- https://nvd.nist.gov/vuln/detail/CVE-2014-6287
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: 'CVE-2014-6287'
cwe-id: CWE-94
epss-score: 0.94363
epss-percentile: 0.99963
cpe: cpe:2.3:a:rejetto:http_file_server:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: rejetto
product: http_file_server
shodan-query: http.favicon.hash:2124459909
fofa-query: icon_hash=2124459909
tags: cve2014,cve,packetstorm,msf,hf
No writeups or analysis indexed.
http://packetstormsecurity.com/files/126869/VMware-Security-Advisory-2014-0005.htmlhttp://secunia.com/advisories/58894http://www.securityfocus.com/archive/1/532236/100/0/threadedhttp://www.securitytracker.com/id/1030310http://www.securitytracker.com/id/1030311http://www.vmware.com/security/advisories/VMSA-2014-0005.htmlhttp://packetstormsecurity.com/files/126869/VMware-Security-Advisory-2014-0005.htmlhttp://secunia.com/advisories/58894http://www.securityfocus.com/archive/1/532236/100/0/threadedhttp://www.securitytracker.com/id/1030310http://www.securitytracker.com/id/1030311http://www.vmware.com/security/advisories/VMSA-2014-0005.html
2014-05-31
Published