First published: Fri Jun 02 2006(Updated: )
VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Server | =1.0.1_build_29996 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2662 is considered a high severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2006-2662, upgrade VMware Server to version RC1 or later, which addresses the credential clearing issue.
CVE-2006-2662 affects VMware Server version 1.0.1_build_29996 and earlier releases.
Local attackers could exploit CVE-2006-2662 to access user credentials stored in memory and escalate privileges.
There are no specific workarounds for CVE-2006-2662 aside from upgrading to a patched version of the software.