NASLDB: VMware Workstation Multiple Vulnerabilities (VMSA-2012-0009)
General
ID: 59092
Name: VMware Workstation Multiple Vulnerabilities (VMSA-2012-0009)
Summary: Checks VMware Workstation version
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS Temporal Vector: CVSS2#E:U/RL:OF/RC:C
Port: –
Family: Windows
Type: Local
Description
The VMware Workstation install detected on the remote host is 7.x
earlier than 7.1.6 or 8.0.x earlier than 8.0.3 and is, therefore,
potentially affected by the following vulnerabilities :
– Memory corruption errors exist related to the
RPC commands handler function which could cause the
application to crash or possibly allow an attacker to
execute arbitrary code. Note that these errors only
affect the 3.x branch. (CVE-2012-1516, CVE-2012-1517)
– An error in the virtual floppy device configuration
can allow out-of-bounds memory writes and can allow
a guest user to crash the VMX process or potentially
execute arbitrary code on the host. Note that root or
administrator level privileges in the guest are required
for successful exploitation along with the existence of
a virtual floppy device in the guest. (CVE-2012-2449)
– An error in the virtual SCSI device registration
process can allow improper memory writes and can allow
a guest user to crash the VMX process or potentially
execute arbitrary code on the host. Note that root or
administrator level privileges are required in the
guest for successful exploitation along with the
existence of a virtual SCSI device in the guest.
(CVE-2012-2450)
Exploiting
Exploit Available: False
Exploitability Ease: No known exploits are available
Sources
CVE: CVE-2012-1516
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2011/05/03
Patch Release: 2011/06/13
Plugin Release: 2012/05/15
Plugin
Version: 1.3
Filename: vmware_workstation_multiple_vmsa_2012_0009.nasl
Filesize: 4409 bytes
MD5 Hash: f0789801bf40523cb3e76afcc12f2c5c
Identification: –
Require Keys: SMB/Registry/Enumerated", "VMware/Workstation/Version
Dependencies: "vmware_workstation_detect.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













