CVE-2015-3650
published 2015-07-10CVE-2015-3650: vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.46%
36.7th percentile
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | horizon_client | — | — |
| vmware | horizon_view_client | — | — |
| vmware | horizon_view_client | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_horizon | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation, Player and Horizon View Client for Windows updates address a host privilege escalation vulnerability
vendor_vmware·2015-07-09·CVSS 7.2
CVE-2015-3650 [HIGH] VMware Workstation, Player and Horizon View Client for Windows updates address a host privilege escalation vulnerability
VMSA-2015-0005: VMware Workstation, Player and Horizon View Client for Windows updates address a host privilege escalation vulnerability
a. VMware Workstation, Player and Horizon View Client for Windows host privilege escalation vulnerability. VMware Workstation, Player and Horizon View Client for Windows do not set a discretionary access control list (DACL) for one of their processes. This may allow a local attacker to elevate their privileges and execute code in the security context of the affected process. VMware would like to thank Kyriakos Economou of Nettitude for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-3650 to this issue. Column 4 of the following table lists the action required to remediate t
GHSA
GHSA-c3fp-4gq7-m24g: vmware-vmx
ghsa_unreviewed·2022-05-17
CVE-2015-3650 [HIGH] CWE-284 GHSA-c3fp-4gq7-m24g: vmware-vmx
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.
No detection rules found.
No public exploits indexed.
Recorded Future
Analyzing Attack Vector Trends by Industry, Country, and More
blogs_recorded_future
Analyzing Attack Vector Trends by Industry, Country, and More
# Analyzing Attack Vector Trends by Industry, Country, and More
Cyber security professionals are flooded with issues requiring their attention. Identifying the most significant risks can be challenging, which makes choosing where to allocate resources even more difficult. This applies to both short term tactical decisions (e.g., Which vulnerabilities do I prioritize this week?) and longer term strategic decisions (e.g., Where do I invest in technology?) for the organization.
Recorded Future provides real-time situational awareness of trending information security topics to support those critical choices. This is done by analyzing millions of documents from the Web daily. The unstructured text from security blogs, threat researchers, mainstream media, and much more is mined and given stru
Recorded Future
Analyzing Attack Vector Trends by Industry, Country, and More
blogs_recorded_future
Analyzing Attack Vector Trends by Industry, Country, and More
## Analyzing Attack Vector Trends by Industry, Country, and More
Cyber security professionals are flooded with issues requiring their attention. Identifying the most significant risks can be challenging, which makes choosing where to allocate resources even more difficult. This applies to both short term tactical decisions (e.g., Which vulnerabilities do I prioritize this week?) and longer term strategic decisions (e.g., Where do I invest in technology?) for the organization.
Recorded Future provides real-time situational awareness of trending information security topics to support those critical choices. This is done by analyzing millions of documents from the Web daily. The unstructured text from security blogs, threat researchers, mainstream media, and much more is mined and given str
http://www.securitytracker.com/id/1032822http://www.securitytracker.com/id/1032823http://www.vmware.com/security/advisories/VMSA-2015-0005.htmlhttps://www.nettitude.co.uk/vmware-multiple-products-privilege-escalation/http://www.securitytracker.com/id/1032822http://www.securitytracker.com/id/1032823http://www.vmware.com/security/advisories/VMSA-2015-0005.htmlhttps://www.nettitude.co.uk/vmware-multiple-products-privilege-escalation/
2015-07-10
Published