CVE-2014-8370
MEDIUM severity · CVSS 6.4 · CWE-264
6.4CVSS MEDIUM
Summary
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impact—
Exploit probability (EPSS)4%
AV:N/AC:L/Au:N/C:N/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://jvn.jp/en/jp/JVN88252465/index.htmlAdvisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000007Advisory
- http://secunia.com/advisories/62551
- http://secunia.com/advisories/62605
- http://secunia.com/advisories/62669
- http://www.securityfocus.com/bid/72338Advisory
- http://www.securitytracker.com/id/1031642Advisory
- http://www.securitytracker.com/id/1031643Advisory