Vulnerability Description
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Open-Vm-Tools | 2009.03.18-154848 |
Related Weaknesses (CWE)
References
- https://bugs.gentoo.org/264577Issue TrackingPatchThird Party Advisory
- https://github.com/vmware/open-vm-tools/releases/tag/2009.03.18-154848Release NotesThird Party Advisory
- https://bugs.gentoo.org/264577Issue TrackingPatchThird Party Advisory
- https://github.com/vmware/open-vm-tools/releases/tag/2009.03.18-154848Release NotesThird Party Advisory
FAQ
What is CVE-2009-1143?
CVE-2009-1143 is a vulnerability with a CVSS score of 7.0 (HIGH). An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in moun...
How severe is CVE-2009-1143?
CVE-2009-1143 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1143?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Open-Vm-Tools.