CVE-2007-5618
Last modified
CVE-2007-5618 is a vulnerability of currently unknown severity. Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Player | >= 1.0.0, < 1.0.5 |
| Vmware | Player | >= 2.0, < 2.0.1 |
| Vmware | Server | < 1.0.4 |
| Vmware | Workstation | >= 5.5, < 5.5.5 |
| Vmware | Workstation | >= 6.0, < 6.0.1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlThird Party Advisory
- http://secunia.com/advisories/26890Third Party Advisory
- http://www.securityfocus.com/archive/1/489739/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28276Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28289Third Party Advisory, VDB Entry
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3229Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0905/referencesThird Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlThird Party Advisory
- http://secunia.com/advisories/26890Third Party Advisory
- http://www.securityfocus.com/archive/1/489739/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28276Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28289Third Party Advisory, VDB Entry
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3229Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0905/referencesThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5618?
How severe is CVE-2007-5618?
How do I fix CVE-2007-5618?
Are you affected by CVE-2007-5618?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
