← Back

CVE-2007-5671

nvd nist
Published: Jun 5, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

Affected (27)

9 products
Ace
Esx
Esx Server
Player
Server
Vmware Player
Vmware Server
Vmware Workstation
Workstation
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Vmware
Version 2.5.4
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 2.5.5
Version 1.0.4
Version 1.0.3
Vmware
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.5
Vmware
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.4
Vmware
Version 5.5.0
Version 5.5.2
Version 5.5.5
Vmware
Version 5.5.1
Version 5.5.3
Version 5.5.4

References (24)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.