HIGH · 8.5

CVE-2010-1141

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 2031...

Vulnerability Description

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, which allows user-assisted remote attackers to execute arbitrary code by tricking a Windows guest OS user into clicking on a file that is stored on a network share.

CVSS Score

8.5

HIGH

AV:N/AC:M/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
VmwareWorkstation6.5.0
MicrosoftWindowsAll versions
VmwarePlayer2.5
VmwareAce2.5.0
VmwareServer2.0.0
VmwareFusion2.0
VmwareEsxi3.5
VmwareEsx2.5.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-1141?

CVE-2010-1141 is a vulnerability with a CVSS score of 8.5 (HIGH). VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 2031...

How severe is CVE-2010-1141?

CVE-2010-1141 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-1141?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Workstation, Microsoft Windows, Vmware Player, Vmware Ace, Vmware Server.