First published: Fri May 04 2007(Updated: )
The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to write to arbitrary memory locations via a crafted poke to I/O port 0x1004, triggering a denial of service (virtual machine crash) or other unspecified impact, a related issue to CVE-2007-1337.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Server | =1.0.1_build_29996 | |
VMware Workstation | =5.5.3_build_34685 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2491 is considered to have a moderate severity level due to its potential to cause denial of service through virtual machine crashes.
To fix CVE-2007-2491, users should upgrade to a version of VMware Server or Workstation that is not affected by this vulnerability.
CVE-2007-2491 affects VMware Workstation version 5.5.3 build 34685 and VMware Server version 1.0.1 build 29996.
Exploiting CVE-2007-2491 can lead to a denial of service primarily by causing crashes of the virtual machines.
CVE-2007-2491 is a local vulnerability that requires local access to exploit, making remote exploitation highly unlikely.