VMware Fusion 5.x < 5.0.4 LGTOSYNC.SYS Privilege Escalation (VMSA-2013-0014)

high Nessus Plugin ID 71230

Synopsis

The remote host has a virtualization application that is affected by a privilege escalation vulnerability.

Description

The version of VMware Fusion 5.x installed on the remote Mac OS X host is prior to 5.0.4. It is, therefore, reportedly affected by a privilege escalation vulnerability in the LGTOSYNC.SYS driver on 32-bit Guest Operating Systems running Windows XP.

Note that by exploiting this issue, a local attacker could elevate his privileges only on the Guest Operating System and not on the host.

Solution

Upgrade to VMware Fusion 5.0.4 or later.

Plugin Details

Severity: High

ID: 71230

File Name: macosx_fusion_5_0_4.nasl

Version: 1.5

Type: local

Agent: macosx

Published: 12/5/2013

Updated: 11/27/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: High

Base Score: 7.9

Temporal Score: 5.8

Vector: CVSS2#AV:A/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2013-3519

Vulnerability Information

CPE: cpe:/a:vmware:fusion

Required KB Items: Host/local_checks_enabled, MacOSX/Fusion/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 11/14/2013

Vulnerability Publication Date: 12/3/2013

Reference Information

CVE: CVE-2013-3519

BID: 64075

VMSA: 2013-0014