Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-1787 | First vendor Publication | 2011-06-06 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 6.9 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1787 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-362 | Race Condition |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20345 | |||
Oval ID: | oval:org.mitre.oval:def:20345 | ||
Title: | VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues | ||
Description: | Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2011-1787 | Version: | 5 |
Platform(s): | VMWare ESX Server 4.1 VMWare ESX Server 4.0 VMWare ESX Server 3.5 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 | |
Application | 3 | |
Application | 3 | |
Application | 4 | |
Application | 3 |
OpenVAS Exploits
Date | Description |
---|---|
2012-03-16 | Name : VMSA-2011-0009.3 VMware hosted product updates, ESX patches and VI Client upd... File : nvt/gb_VMSA-2011-0009.nasl |
2011-06-13 | Name : VMware Products Multiple Vulnerabilities (Linux) -june11 File : nvt/gb_vmware_prdts_mult_vuln_lin_jun11.nasl |
2011-06-13 | Name : VMware Products Multiple Vulnerabilities (Win) - jun 11 File : nvt/gb_vmware_prdts_mult_vuln_win_jun11.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73240 | VMware Multiple Products mount.vmhgfs Race Condition Filesystem Mounting Loca... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2011-06-09 | IAVM : 2011-A-0075 - Multiple Vulnerabilities in VMware Products Severity : Category I - VMSKEY : V0028311 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-03-04 | Name : The remote VMware ESX / ESXi host is missing a security-related patch. File : vmware_VMSA-2011-0009_remote.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_libvmtools-devel-110607.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_4_libvmtools-devel-110608.nasl - Type : ACT_GATHER_INFO |
2013-11-13 | Name : The remote VMware ESXi 5.0 host is affected by multiple security vulnerabilit... File : vmware_esxi_5_0_build_515841_remote.nasl - Type : ACT_GATHER_INFO |
2011-06-08 | Name : The remote host has a virtualization application affected by multiple vulnera... File : vmware_multiple_vmsa_2011_0009.nasl - Type : ACT_GATHER_INFO |
2011-06-07 | Name : The remote Windows host has a COM object that is affected by a memory corrupt... File : tomsawyer_get_extension_factory_activex.nasl - Type : ACT_GATHER_INFO |
2011-06-06 | Name : The remote host has a virtualization application affected by multiple vulnera... File : macosx_fusion_3_1_3.nasl - Type : ACT_GATHER_INFO |
2011-06-06 | Name : The remote VMware ESXi / ESX host is missing one or more security-related pat... File : vmware_VMSA-2011-0009.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:04 |
|
2024-11-28 12:25:38 |
|
2021-05-04 12:14:25 |
|
2021-04-22 01:15:41 |
|
2020-05-23 00:28:26 |
|
2016-04-26 20:44:21 |
|
2016-03-05 13:26:42 |
|
2014-11-14 13:27:12 |
|
2014-06-14 13:30:44 |
|
2014-02-17 11:02:09 |
|
2013-11-11 12:39:20 |
|
2013-05-10 22:59:44 |
|