CVE-2017-4919
published 2017-07-28CVE-2017-4919: VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without…
PriorityP351critical9CVSS 3.0
AVNACHPRNUINSCCHIHAH
EPSS
2.04%
78.9th percentile
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.09.0CRITICALCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware VIX API VM Direct Access Function security issue
vendor_vmware·2017-07-27·CVSS 9.0
CVE-2017-4919 [CRITICAL] VMware VIX API VM Direct Access Function security issue
VMSA-2017-0012: VMware VIX API VM Direct Access Function security issue
VMware VIX API VM Direct Access Function security issue The VMware VIX API has a functionality that allows for direct access to Guests OSs which is used by VMware Site Recovery Manager, VMware Update Manager, and VMware Infrastructure Navigator to manage Guest OSs. This functionality may be used by vSphere users with limited privileges to access a Guest OS without the need to authenticate. In order for vSphere users with limited privileges to use this functionality, they would need to have all three of the following privileges: Virtual Machine -> Configuration -> Advanced Virtual Machine -> Interaction -> Guest Operating System Management by VIX API Host -> Configuration -> Advanced Settings
CVEs: CVE-2017-4919
Affec
GHSA
GHSA-h7jp-76rq-hgj5: VMware vCenter Server 5
ghsa_unreviewed·2022-05-13
CVE-2017-4919 [CRITICAL] CWE-306 GHSA-h7jp-76rq-hgj5: VMware vCenter Server 5
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-07-28
Published