Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-1363 | First vendor Publication | 2008-03-19 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1363 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-234 | Hijacking a privileged process |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-10-03 | Name : Gentoo Security Advisory GLSA 201209-25 (vmware-server vmware-player vmware-w... File : nvt/glsa_201209_25.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
43897 | VMware Multiple Products Application Data Folder config.ini Handling Local P... VMware Server contains a flaw that may allow a malicious local user to gain access to unauthorized privileges. The issue is triggered when 'authd' connects to opened pipes controled by the attacker occurs. This flaw may lead to a loss of Confidentiality and Integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-10-01 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201209-25.nasl - Type : ACT_GATHER_INFO |
2008-04-02 | Name : The remote Windows host has an application that is affected by multiple issues. File : vmware_multiple_vmsa_2008_0005.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:14:47 |
|
2024-11-28 12:15:12 |
|
2020-05-23 01:39:16 |
|
2020-05-23 00:21:27 |
|
2018-11-30 12:02:23 |
|
2018-11-01 21:19:44 |
|
2018-11-01 17:19:02 |
|
2018-10-31 21:20:04 |
|
2018-10-12 00:20:16 |
|
2017-08-08 09:23:57 |
|
2016-06-28 17:12:44 |
|
2016-04-26 17:14:05 |
|
2014-02-17 10:44:16 |
|
2013-05-16 17:02:27 |
|
2013-05-11 00:12:35 |
|