CVE-2007-5023: Medium severity VMware Workstation vulnerability
Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5023?
CVE-2007-5023 is classified as a high-severity vulnerability that allows local users to gain elevated privileges on affected systems.
How do I fix CVE-2007-5023?
To fix CVE-2007-5023, upgrade to the latest version of the affected VMware products, which have the vulnerability patched.
Which VMware products are affected by CVE-2007-5023?
CVE-2007-5023 affects versions of VMware Workstation prior to 5.5.5 and 6.x prior to 6.0.1, Player prior to 1.0.5 and 2.0.1, ACE prior to 1.0.3, and Server prior to 1.0.4.
How can attackers exploit CVE-2007-5023?
Attackers can exploit CVE-2007-5023 by manipulating the unquoted Windows search path to execute malicious code with elevated privileges.
Is there a workaround for CVE-2007-5023?
A potential workaround for CVE-2007-5023 involves renaming the affected executables to eliminate spaces in the file paths, but upgrading is the recommended solution.