MEDIUM · 4.4

CVE-2007-5671

HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 8...

Vulnerability Description

HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

CVSS Score

4.4

MEDIUM

AV:L/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
VmwareAce1.0.0
VmwareEsx Server2.5.5
VmwarePlayer1.0.4
VmwareServer1.0.3
VmwareVmware Player1.0.0
VmwareVmware Server1.0.0
VmwareVmware Workstation5.5.0
VmwareWorkstation5.5.1
VmwareEsx2.5.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5671?

CVE-2007-5671 is a vulnerability with a CVSS score of 4.4 (MEDIUM). HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 8...

How severe is CVE-2007-5671?

CVE-2007-5671 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5671?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Ace, Vmware Esx Server, Vmware Player, Vmware Server, Vmware Vmware Player.