CVE-2014-8370
published 2015-01-29CVE-2014-8370: VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
4.19%
89.8th percentile
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues
vendor_vmware·2015-01-27·CVSS 6.4
CVE-2014-3513 [MEDIUM] VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues
VMSA-2015-0001: VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues
a. VMware ESXi, Workstation, Player, and Fusion host privilege escalation vulnerability VMware ESXi, Workstation, Player and Fusion contain an arbitrary file write issue. Exploitation this issue may allow for privilege escalation on the host. The vulnerability does not allow for privilege escalation from the guest Operating System to the host or vice-versa. This means that host memory can not be manipulated from the Guest Operating System. Mitigation For ESXi to be affected, permissions must have been added to ESXi (or a vCenter Server managing it) for a virtual machine administrator role or greater. VMware would like to thank Shanon Olsson for reporting this issue to us through JP
GHSA
GHSA-3g8q-4222-255f: VMware Workstation 10
ghsa_unreviewed·2022-05-17
CVE-2014-8370 [MEDIUM] GHSA-3g8q-4222-255f: VMware Workstation 10
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://jvn.jp/en/jp/JVN88252465/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2015-000007http://secunia.com/advisories/62551http://secunia.com/advisories/62605http://secunia.com/advisories/62669http://www.securityfocus.com/bid/72338http://www.securitytracker.com/id/1031642http://www.securitytracker.com/id/1031643http://www.vmware.com/security/advisories/VMSA-2015-0001.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100933http://jvn.jp/en/jp/JVN88252465/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2015-000007http://secunia.com/advisories/62551http://secunia.com/advisories/62605http://secunia.com/advisories/62669http://www.securityfocus.com/bid/72338http://www.securitytracker.com/id/1031642http://www.securitytracker.com/id/1031643http://www.vmware.com/security/advisories/VMSA-2015-0001.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100933
2015-01-29
Published