VMware Tools is prone to an local information-disclosure vulnerability.
Exploiting this issue may allow a local attacker to obtain sensitive information that may aid in further attacks. Failed exploit attempts will likely cause a denial-of-service condition.
VMware Tools versions 10.x are vulnerable.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
| Bugtraq ID: | 108673 |
| Class: | Design Error |
| CVE: | CVE-2019-5522 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 06 2019 12:00AM |
| Updated: | Jun 06 2019 12:00AM |
| Credit: | ChenNan and RanchoIce of Tencent ZhanluLab |
| Vulnerable: | VMWare Tools 10.3 VMWare Tools 10.0.6 VMWare Tools 10.0.5 VMWare Tools 10.1.10.6082533 VMWare Tools 10.1.0 VMWare Tools 10.0.9 VMWare Tools 10.0.0.3000743 VMWare Tools 10.0 |
| Not Vulnerable: | VMWare Tools 10.3.10 |
from SecurityFocus Vulnerabilities http://bit.ly/2WLQkyJ
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.