VMware Multiple Product vmci.sys VMCI Control Code Handling Local Privilege Escalation Vulnerability
2 Apr. 2013
Summary
VMware Multiple Product vmci.sys Virtual Machine Communication Interface (VMCI) control suffers from code handling local privilege escalation vulnerability.
Vulnerable Systems:
* VMware Workstation 9.0 and prior
* VMware Fusion 5.0.1 and prior
* VMware ESX 4.1 and prior
* VMware ESXi 5.1 and prior
* VMware View 4.6.1 and prior
Multiple VMware products contain a flaw in the Virtual Machine Communication Interface (VMCI) that leads to unauthorized privileges being gained. The issue is triggered when handling control code and may allow a local attacker to change memory allocation and gain escalated privileges.