CVE-2015-6933
published 2016-01-09CVE-2015-6933: The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before…
PriorityP333medium6.3CVSS 3.0
AVNACLPRLUINSUCLILAL
EPSS
1.51%
71.6th percentile
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability
vendor_vmware·2016-01-07·CVSS 6.3
CVE-2015-6933 [MEDIUM] VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability
VMSA-2016-0001: VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability
Important Windows-based guest privilege escalation in VMware Tools A kernel memory corruption vulnerability is present in the VMware Tools "Shared Folders" (HGFS) feature running on Microsoft Windows. Successful exploitation of this issue could lead to an escalation of privilege in the guest operating system. VMware would like to thank Dmitry Janushkevich from the Secunia Research Team for reporting this issue to us. Note: This vulnerability does not allow for privilege escalation from the guest operating system to the host. Host memory can not be manipulated from the guest operating system by exploiting this flaw. The Common Vulnerabilities and Exposures project
GHSA
GHSA-gh38-v7fv-5hxj: The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11
ghsa_unreviewed·2022-05-17
CVE-2015-6933 [MEDIUM] CWE-284 GHSA-gh38-v7fv-5hxj: The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-01-09
Published