CVE-2016-5330
published 2016-08-08CVE-2016-5330: Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro…
PriorityP354high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
18.02%
96.9th percentile
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | 5.0 – 6.0 | — |
| vmware | fusion | >= 8.1 < 8.1.1 | 8.1.1 |
| vmware | tools | 9.0.0 – 10.3.22 | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | >= 12.1.0 < 12.1.1 | 12.1.1 |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | >= 12.1.0 < 12.1.1 | 12.1.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r9pr-hcq4-m3jp: Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10
ghsa_unreviewed·2022-05-13
CVE-2016-5330 [HIGH] CWE-426 GHSA-r9pr-hcq4-m3jp: Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
VMware
VMware product updates address multiple security issues
vendor_vmware·2016-08-04·CVSS 7.8
CVE-2016-5330 [HIGH] VMware product updates address multiple security issues
VMSA-2016-0010: VMware product updates address multiple security issues
a. DLL hijacking issue in Windows-based VMware Tools A DLL hijacking vulnerability is present in the VMware Tools "Shared Folders" (HGFS) feature running on Microsoft Windows. Exploitation of this issue may lead to arbitrary code execution with the privileges of the victim. In order to exploit this issue, the attacker would need write access to a network share and they would need to entice the local user into opening their document. There are no known workarounds for this issue. VMware would like to thank Yorick Koster of Securify B.V. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-5330 to this issue. Column 5 of the following table
No detection rules found.
Exploit-DB
VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
exploitdb·2016-08-06
CVE-2016-5330 VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
---
require 'msf/core'
class MetasploitModule 'DLL Side Loading Vulnerability in VMware Host Guest Client Redirector',
'Description' => %q{
A DLL side loading vulnerability was found in the VMware Host Guest Client Redirector,
a component of VMware Tools. This issue can be exploited by luring a victim into
opening a document from the attacker's share. An attacker can exploit this issue to
execute arbitrary code with the privileges of the target user. This can potentially
result in the attacker taking complete control of the affected system. If the WebDAV
Mini-Redirector is enabled, it is possible to exploit this issue over the internet.
},
'Author' => 'Yorick Koster',
'License' => MSF_LICENSE,
'References' =>
[
['CVE',
Metasploit
DLL Side Loading Vulnerability in VMware Host Guest Client Redirector
metasploit
DLL Side Loading Vulnerability in VMware Host Guest Client Redirector
DLL Side Loading Vulnerability in VMware Host Guest Client Redirector
A DLL side loading vulnerability was found in the VMware Host Guest Client Redirector, a component of VMware Tools. This issue can be exploited by luring a victim into opening a document from the attacker's share. An attacker can exploit this issue to execute arbitrary code with the privileges of the target user. This can potentially result in the attacker taking complete control of the affected system. If the WebDAV Mini-Redirector is enabled, it is possible to exploit this issue over the internet.
No writeups or analysis indexed.
http://www.rapid7.com/db/modules/exploit/windows/misc/vmhgfs_webdav_dll_sideloadhttp://www.securityfocus.com/archive/1/539131/100/0/threadedhttp://www.securityfocus.com/bid/92323http://www.securitytracker.com/id/1036544http://www.securitytracker.com/id/1036545http://www.securitytracker.com/id/1036619http://www.vmware.com/security/advisories/VMSA-2016-0010.htmlhttps://securify.nl/advisory/SFY20151201/dll_side_loading_vulnerability_in_vmware_host_guest_client_redirector.htmlhttp://www.rapid7.com/db/modules/exploit/windows/misc/vmhgfs_webdav_dll_sideloadhttp://www.securityfocus.com/archive/1/539131/100/0/threadedhttp://www.securityfocus.com/bid/92323http://www.securitytracker.com/id/1036544http://www.securitytracker.com/id/1036545http://www.securitytracker.com/id/1036619http://www.vmware.com/security/advisories/VMSA-2016-0010.htmlhttps://securify.nl/advisory/SFY20151201/dll_side_loading_vulnerability_in_vmware_host_guest_client_redirector.html
2016-08-08
Published