Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder.
References
Link | Resource |
---|---|
http://www.vmware.com/support/ace/doc/releasenotes_ace.html | Patch Vendor Advisory |
http://www.vmware.com/support/player/doc/releasenotes_player.html | Patch Vendor Advisory |
http://www.vmware.com/support/player2/doc/releasenotes_player2.html | Patch Vendor Advisory |
http://www.vmware.com/support/server/doc/releasenotes_server.html | Patch Vendor Advisory |
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html | Patch Vendor Advisory |
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/25732 | Patch Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2007-09-21 12:17
Updated : 2019-08-01 05:21
NVD link : CVE-2007-5023
Mitre link : CVE-2007-5023
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
vmware
- ace
- workstation
- player
- server
canonical
- ubuntu_linux