|
|
| |
| Multiple VMware products are prone to a command-injection vulnerability that exists in VMware Tools. |
| |
Credit:
The information has been provided by Nahuel Grisolia.
The original article can be found at: http://www.securityfocus.com/bid/45166
|
| |
Vulnerable Systems:
* VMWare ESXi Server 4.1
A local attacker on the host system can exploit this issue to execute arbitrary commands on the guest operating system with root privileges.
Vendor Status:
VMware had issued an update for this vulnerability
Patch Availability:
http://www.vmware.com/security/advisories/VMSA-2010-0018.html
CVE Information:
CVE-2010-4297
Disclosure Timeline:
Issue date: 2010-12-02
Updated on: 2010-12-02 (initial release of advisory)
|
|
blog comments powered by
|