CVE-2000-0090: Low severity VMware Workstation vulnerability
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
VMware Workstation and ESXifrom your environment.If the product is not required, uninstall or stop VMware Workstation and ESXi instances running version 1.1.2 until a vendor-supplied patch is released.
- Compensating control
Restrict and monitor local user access on hosts running VMware Workstation and ESXi to trusted administrative accounts only. Apply least-privilege policies, disable or remove untrusted local accounts, and isolate affected hosts from untrusted users to mitigate symlink-based local DoS attempts.
- Operational
Inventory systems to identify any instances of VMware running version 1.1.2. If found, isolate those hosts from production networks and avoid executing untrusted local processes until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0090?
CVE-2000-0090 is classified as a medium severity vulnerability due to its ability to cause a denial of service.
How do I fix CVE-2000-0090?
To fix CVE-2000-0090, upgrade to a later version of VMware Workstation that is not affected.
Who is affected by CVE-2000-0090?
Users of VMware Workstation versions 1.0.1, 1.0.2, 1.1, 1.1.1, and 1.1.2 are affected by CVE-2000-0090.
What type of attack is associated with CVE-2000-0090?
CVE-2000-0090 is associated with a local symlink attack that can lead to denial of service.
Is CVE-2000-0090 a remote attack vulnerability?
No, CVE-2000-0090 is a local vulnerability and requires local access to exploit.