VMSA-2016-0001 : VMware ESXi, Workstation, Player, and Fusion updates address important guest privilege escalation vulnerability

medium Nessus Plugin ID 87889

Synopsis

The remote VMware ESXi host is missing a security-related patch.

Description

Important Windows-based guest privilege escalation in VMware Tools

A kernel memory corruption vulnerability is present in the VMware Tools 'Shared Folders' (HGFS) feature running on Microsoft Windows. Successful exploitation of this issue could lead to an escalation of privilege in the guest operating system.

VMware would like to thank Dmitry Janushkevich from the Secunia Research Team for reporting this issue to us.

Note: This vulnerability does not allow for privilege escalation from the guest operating system to the host. Host memory can not be manipulated from the guest operating system by exploiting this flaw.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-6933 to this issue.

Workarounds Removing the 'Shared Folders' (HGFS) feature from previously installed VMware Tools will remove the possibility of exploitation.

Solution

Apply the missing patch.

See Also

http://lists.vmware.com/pipermail/security-announce/2016/000316.html

Plugin Details

Severity: Medium

ID: 87889

File Name: vmware_VMSA-2016-0001.nasl

Version: 1.17

Type: local

Published: 1/13/2016

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:vmware:esxi:5.0, cpe:/o:vmware:esxi:5.1, cpe:/o:vmware:esxi:5.5, cpe:/o:vmware:esxi:6.0

Required KB Items: Host/local_checks_enabled, Host/VMware/release, Host/VMware/version

Exploit Ease: No known exploits are available

Patch Publication Date: 1/7/2016

Reference Information

CVE: CVE-2015-6933

VMSA: 2016-0001