MEDIUM · 6.9

CVE-2008-4915

The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0...

Vulnerability Description

The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
VmwareAce>= 1.0, <= 1.0.7
VmwareEsx>= 2.5.4, <= 3.5
VmwareEsxi3.5
VmwarePlayer>= 1.0.0, <= 1.0.8
VmwareServer>= 1.0, <= 1.0.7
VmwareWorkstation>= 5.5, <= 5.5.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-4915?

CVE-2008-4915 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0...

How severe is CVE-2008-4915?

CVE-2008-4915 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-4915?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Ace, Vmware Esx, Vmware Esxi, Vmware Player, Vmware Server.