CVE-2006-2662: Medium severity vmware server vulnerability
Published Jun 2, 2006
·Updated
VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges.
Affected Software
1 affected component
VMware Server=1.0.1_build_29996
Remediation
Event History
Jun 2, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2662?
CVE-2006-2662 is considered a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2006-2662?
To fix CVE-2006-2662, upgrade VMware Server to version RC1 or later, which addresses the credential clearing issue.
3
Who is affected by CVE-2006-2662?
CVE-2006-2662 affects VMware Server version 1.0.1_build_29996 and earlier releases.
4
What kind of attacks are possible due to CVE-2006-2662?
Local attackers could exploit CVE-2006-2662 to access user credentials stored in memory and escalate privileges.
5
Is there a workaround for CVE-2006-2662?
There are no specific workarounds for CVE-2006-2662 aside from upgrading to a patched version of the software.