Vulnerability Description
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Ace | >= 1.0, <= 1.0.7 |
| Vmware | Esx | >= 2.5.4, <= 3.5 |
| Vmware | Esxi | 3.5 |
| Vmware | Player | >= 1.0.0, <= 1.0.8 |
| Vmware | Server | >= 1.0, <= 1.0.7 |
| Vmware | Workstation | >= 5.5, <= 5.5.8 |
Related Weaknesses (CWE)
References
- http://lists.vmware.com/pipermail/security-announce/2008/000042.htmlVendor Advisory
- http://secunia.com/advisories/32612Third Party Advisory
- http://secunia.com/advisories/32624Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://www.securityfocus.com/archive/1/498138/100/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/32168Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1021154Third Party AdvisoryVDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0018.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2008/3052Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46415Third Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2008/000042.htmlVendor Advisory
- http://secunia.com/advisories/32612Third Party Advisory
- http://secunia.com/advisories/32624Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
FAQ
What is CVE-2008-4915?
CVE-2008-4915 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0...
How severe is CVE-2008-4915?
CVE-2008-4915 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4915?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Ace, Vmware Esx, Vmware Esxi, Vmware Player, Vmware Server.