CVE-2017-4922
published 2017-08-01CVE-2017-4922: VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.32%
67.8th percentile
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vr8-x3cf-hqhj: VMware vCenter Server (6
ghsa_unreviewed·2022-05-17
CVE-2017-4922 [MEDIUM] CWE-200 GHSA-5vr8-x3cf-hqhj: VMware vCenter Server (6
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
VMware
VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
vendor_vmware·2017-07-27·CVSS 6.7
CVE-2015-5191 [MEDIUM] VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
VMSA-2017-0013: VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
a. Insecure library loading through LD_LIBRARY_PATH VMware vCenter Server contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation. Note: In order to exploit this issue an attacker should be able to trick the admin to execute wrapper scripts from a world writable directory. VMware would like to thank Thorsten Tüllmann, researcher at Karlsruhe Institute of Technology for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-01
Published