CVE-2017-4921
published 2017-08-01CVE-2017-4921: VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe…
PriorityP347high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.67%
74.2th percentile
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvwm-vf9r-8r57: VMware vCenter Server (6
ghsa_unreviewed·2022-05-13
CVE-2017-4921 [HIGH] GHSA-cvwm-vf9r-8r57: VMware vCenter Server (6
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
VMware
VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
vendor_vmware·2017-07-27·CVSS 6.7
CVE-2015-5191 [MEDIUM] VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
VMSA-2017-0013: VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
a. Insecure library loading through LD_LIBRARY_PATH VMware vCenter Server contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation. Note: In order to exploit this issue an attacker should be able to trick the admin to execute wrapper scripts from a world writable directory. VMware would like to thank Thorsten Tüllmann, researcher at Karlsruhe Institute of Technology for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-01
Published