Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title VMware View privilege escalation and cross-site scripting
Informations
Name VMSA-2012-0004 First vendor Publication 2012-03-15
Vendor VMware Last vendor Modification 2012-03-15
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 7.2 Attack Range Local
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

a. VMware Virtual Desktop Display Driver Privilege Escalation

The VMware XPDM and WDDM display drivers contain buffer overflow vulnerabilities and the XPDM display driver does not properly check for NULL pointers. Exploitation of these issues may lead to local privilege escalation on View virtual desktops.

VMware would like to thank Tarjei Mandt for reporting theses issues to us.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2012-1509 (XPDM buffer overrun), CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null pointer dereference) to these issues.

b. View Manager Portal Cross-site Scripting

A cross-site scripting vulnerability in View Manager Portal may allow a remote attacker to run scripts in the victim's browser. The attacker can trigger this vulnerability by supplying a crafted URL to the victim and convincing them to click on the link.

VMware would like to thank Jeremy Conway for reporting this issue to us.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-1511 to this issue.

Original Source

Url : http://www.vmware.com/security/advisories/VMSA-2012-0004.html

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
25 % CWE-264 Permissions, Privileges, and Access Controls
25 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:16664
 
Oval ID: oval:org.mitre.oval:def:16664
Title: View Manager Portal Cross-site Scripting
Description: Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Family: windows Class: vulnerability
Reference(s): CVE-2012-1511
Version: 4
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): VMware View
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:17151
 
Oval ID: oval:org.mitre.oval:def:17151
Title: VMware Tools Display Driver Privilege Escalation
Description: Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2012-1509
Version: 4
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): VMware View
VMware Workstation
VMware Player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:17183
 
Oval ID: oval:org.mitre.oval:def:17183
Title: VMware Tools Display Driver Privilege Escalation
Description: The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2012-1508
Version: 4
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): VMware View
VMware Workstation
VMware Player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:17258
 
Oval ID: oval:org.mitre.oval:def:17258
Title: VMware Tools Display Driver Privilege Escalation
Description: Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2012-1510
Version: 4
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): VMware View
VMware Workstation
VMware Player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:20252
 
Oval ID: oval:org.mitre.oval:def:20252
Title: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
Description: Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
Family: unix Class: vulnerability
Reference(s): CVE-2012-1510
Version: 4
Platform(s): VMWare ESX Server 4.1
VMWare ESX Server 4.0
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:20278
 
Oval ID: oval:org.mitre.oval:def:20278
Title: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
Description: Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.
Family: unix Class: vulnerability
Reference(s): CVE-2012-1509
Version: 4
Platform(s): VMWare ESX Server 4.1
VMWare ESX Server 4.0
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:20594
 
Oval ID: oval:org.mitre.oval:def:20594
Title: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
Description: The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
Family: unix Class: vulnerability
Reference(s): CVE-2012-1508
Version: 4
Platform(s): VMWare ESX Server 4.1
VMWare ESX Server 4.0
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2
Application 4
Os 3

OpenVAS Exploits

Date Description
2012-03-16 Name : VMSA-2012-0005 VMware vCenter Server, Orchestrator, Update Manager, vShield, ...
File : nvt/gb_VMSA-2012-0005.nasl

Information Assurance Vulnerability Management (IAVM)

Date Description
2012-03-29 IAVM : 2012-A-0045 - VMWare ESX 4.0 and ESXi 4.0 Display Driver Buffer Overflow Vulnerability
Severity : Category I - VMSKEY : V0031898
2012-03-29 IAVM : 2012-A-0046 - VMWare ESX 4.1 and ESXi 4.1 Display Driver Buffer Overflow Vulnerabilities
Severity : Category I - VMSKEY : V0031899
2012-03-29 IAVM : 2012-A-0049 - Multiple Vulnerabilities in VMware View
Severity : Category I - VMSKEY : V0031902

Nessus® Vulnerability Scanner

Date Description
2016-03-03 Name : The remote VMware ESXi / ESX host is missing a security-related patch.
File : vmware_VMSA-2012-0005_remote.nasl - Type : ACT_GATHER_INFO
2013-01-24 Name : The remote host has a virtual desktop solution that is potentially affected b...
File : vmware_view_multiple_vmsa_2012_0004.nasl - Type : ACT_GATHER_INFO
2012-03-16 Name : The remote VMware ESXi / ESX host is missing one or more security-related pat...
File : vmware_VMSA-2012-0005.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 12:07:22
  • Multiple Updates
2013-11-11 12:41:40
  • Multiple Updates