CVE-2016-5331
published 2016-08-08CVE-2016-5331: CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP…
PriorityP429medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.91%
77.4th percentile
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vcenter_server | <= 6.0 | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware product updates address multiple security issues
vendor_vmware·2016-08-04·CVSS 7.8
CVE-2016-5330 [HIGH] VMware product updates address multiple security issues
VMSA-2016-0010: VMware product updates address multiple security issues
a. DLL hijacking issue in Windows-based VMware Tools A DLL hijacking vulnerability is present in the VMware Tools "Shared Folders" (HGFS) feature running on Microsoft Windows. Exploitation of this issue may lead to arbitrary code execution with the privileges of the victim. In order to exploit this issue, the attacker would need write access to a network share and they would need to entice the local user into opening their document. There are no known workarounds for this issue. VMware would like to thank Yorick Koster of Securify B.V. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-5330 to this issue. Column 5 of the following table
GHSA
GHSA-gv3r-q3q8-2h79: CRLF injection vulnerability in VMware vCenter Server 6
ghsa_unreviewed·2022-05-14
CVE-2016-5331 [MEDIUM] CWE-93 GHSA-gv3r-q3q8-2h79: CRLF injection vulnerability in VMware vCenter Server 6
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/138211/VMware-vSphere-Hypervisor-ESXi-HTTP-Response-Injection.htmlhttp://seclists.org/fulldisclosure/2016/Aug/38http://www.securityfocus.com/archive/1/539128/100/0/threadedhttp://www.securityfocus.com/bid/92324http://www.securitytracker.com/id/1036543http://www.securitytracker.com/id/1036544http://www.securitytracker.com/id/1036545http://www.vmware.com/security/advisories/VMSA-2016-0010.htmlhttp://packetstormsecurity.com/files/138211/VMware-vSphere-Hypervisor-ESXi-HTTP-Response-Injection.htmlhttp://seclists.org/fulldisclosure/2016/Aug/38http://www.securityfocus.com/archive/1/539128/100/0/threadedhttp://www.securityfocus.com/bid/92324http://www.securitytracker.com/id/1036543http://www.securitytracker.com/id/1036544http://www.securitytracker.com/id/1036545http://www.vmware.com/security/advisories/VMSA-2016-0010.html
2016-08-08
Published