VMware Workstation Multiple Vulnerabilities (VMSA-2012-0009)

high Nessus Plugin ID 59092

Synopsis

The remote host has a virtualization application that is affected by multiple vulnerabilities.

Description

The VMware Workstation install detected on the remote host is 7.x earlier than 7.1.6 or 8.0.x earlier than 8.0.3 and is, therefore, potentially affected by the following vulnerabilities :

- Memory corruption errors exist related to the RPC commands handler function which could cause the application to crash or possibly allow an attacker to execute arbitrary code. Note that these errors only affect the 3.x branch. (CVE-2012-1516, CVE-2012-1517)

- An error in the virtual floppy device configuration can allow out-of-bounds memory writes and can allow a guest user to crash the VMX process or potentially execute arbitrary code on the host. Note that root or administrator level privileges in the guest are required for successful exploitation along with the existence of a virtual floppy device in the guest. (CVE-2012-2449)

- An error in the virtual SCSI device registration process can allow improper memory writes and can allow a guest user to crash the VMX process or potentially execute arbitrary code on the host. Note that root or administrator level privileges are required in the guest for successful exploitation along with the existence of a virtual SCSI device in the guest.
(CVE-2012-2450)

Solution

Upgrade to VMware Workstation 7.1.6 / 8.0.3 or later.

See Also

http://www.vmware.com/security/advisories/VMSA-2012-0009.html

http://lists.vmware.com/pipermail/security-announce/2012/000176.html

http://www.nessus.org/u?dd5ac32f

http://www.nessus.org/u?0a550479

Plugin Details

Severity: High

ID: 59092

File Name: vmware_workstation_multiple_vmsa_2012_0009.nasl

Version: 1.9

Type: local

Agent: windows

Family: Windows

Published: 5/15/2012

Updated: 3/27/2024

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2012-1516

Vulnerability Information

CPE: cpe:/a:vmware:workstation

Required KB Items: SMB/Registry/Enumerated, Host/VMware Workstation/Version, VMware/Workstation/Path

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/13/2011

Vulnerability Publication Date: 5/3/2011

Reference Information

CVE: CVE-2012-1516, CVE-2012-1517, CVE-2012-2449, CVE-2012-2450

BID: 53369

VMSA: 2012-0009