CVE-2014-8370

CWE-2643 documents3 sources
Severity
6.4MEDIUM
EPSS
1.0%
top 22.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateMay 17

Description

VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages4 packages

NVDvmware/esxi5.0, 5.1, 5.5+2
NVDvmware/fusion5 versions+4
NVDvmware/player5 versions+4
NVDvmware/workstation5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3g8q-4222-255f: VMware Workstation 102022-05-17
CVEList
CVE-2014-8370: VMware Workstation 102015-01-29
CVE-2014-8370 (MEDIUM CVSS 6.4) | VMware Workstation 10.x before 10.0 | cvebase.io