CVE-2007-4496
Last modified
CVE-2007-4496 is a vulnerability of currently unknown severity. Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest operating system to corrupt memory and possibly execute arbitrary code on the host operating system via unspecified vectors.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest operating system to corrupt memory and possibly execute arbitrary code on the host operating system via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Ace | >= 1.0, <= 1.0.3 |
| Vmware | Ace | >= 2.0, <= 2.0.1 |
| Vmware | Player | >= 1.0.0, <= 1.0.5 |
| Vmware | Player | >= 2.0, <= 2.0.1 |
| Vmware | Server | >= 1.0, <= 1.0.4 |
| Vmware | Workstation | >= 5, <= 5.5.5 |
| Vmware | Workstation | >= 6.0, <= 6.0.1 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
| Canonical | Ubuntu Linux | 7.04 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlThird Party Advisory
- http://secunia.com/advisories/26890Third Party Advisory
- http://secunia.com/advisories/27694Third Party Advisory
- http://secunia.com/advisories/27706Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200711-23.xmlThird Party Advisory
- http://www.securityfocus.com/bid/25728Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018718Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-543-1Third Party Advisory
- http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3229Permissions Required
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlThird Party Advisory
- http://secunia.com/advisories/26890Third Party Advisory
- http://secunia.com/advisories/27694Third Party Advisory
- http://secunia.com/advisories/27706Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200711-23.xmlThird Party Advisory
- http://www.securityfocus.com/bid/25728Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018718Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-543-1Third Party Advisory
- http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3229Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4496?
How severe is CVE-2007-4496?
How do I fix CVE-2007-4496?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4490Multiple buffer overflows in EarthAgent.exe in Trend Micro S…
- CVE-2007-4491SQL injection vulnerability in uyeler2.php in Gurur haber 2.…
- CVE-2007-4492Multiple unspecified vulnerabilities in the ata disk driver …
- CVE-2007-4493eZ publish before 3.8.9, and 3.9 before 3.9.3, does not prop…
- CVE-2007-4494The tipafriend function in eZ publish before 3.8.9, and 3.9 …
- CVE-2007-4495Unspecified vulnerability in the ata disk driver in Sun Sola…
- CVE-2007-4497Unspecified vulnerability in EMC VMware Workstation before 5…
- CVE-2007-4498The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Lo…
- CVE-2007-4499Unrestricted file upload vulnerability in output.php in Amer…
- CVE-2007-4500Unspecified vulnerability in TunnelRunner in SSHKeychain bef…
- CVE-2007-4501Unspecified vulnerability in PassphraseRequester in SSHKeych…
- CVE-2007-4502SQL injection vulnerability in index.php in the BibTeX compo…
Are you affected by CVE-2007-4496?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
