First published: Sat Oct 13 2007(Updated: )
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 might allow local users to cause a denial of service to the Virtual Disk Mount Service (vmount2.exe), related to the ConnectPopulatedDiskEx function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ACE | =1.0 | |
VMware ACE | =1.0.1 | |
VMware ACE | =1.0.2 | |
VMware ACE | =1.0.3 | |
VMware ACE | =1.0.4 | |
VMware ACE | =1.0.5 | |
VMware ACE | =1.0.6 | |
VMware ACE | =1.0.7 | |
VMware ACE | =2.0 | |
VMware ACE | =2.0.1 | |
VMware ACE | =2.0.2 | |
VMware ACE | =2.0.3 | |
VMware ACE | =2.0.4 | |
VMware ACE | =2.0.5 | |
VMware Player | =1.0.0 | |
VMware Player | =1.0.1 | |
VMware Player | =1.0.2 | |
VMware Player | =1.0.3 | |
VMware Player | =1.0.4 | |
VMware Player | =1.0.5 | |
VMware Player | =1.0.6 | |
VMware Player | =1.0.7 | |
VMware Player | =1.0.8 | |
VMware Player | =2.0 | |
VMware Player | =2.0.1 | |
VMware Player | =2.0.2 | |
VMware Player | =2.0.3 | |
VMware Player | =2.0.4 | |
VMware Player | =2.0.5 | |
VMware Server | <=1.0.7 | |
VMware Server | =1.0 | |
VMware Server | =1.0.1 | |
VMware Server | =1.0.2 | |
VMware Server | =1.0.3 | |
VMware Server | =1.0.4 | |
VMware Server | =1.0.5 | |
VMware Server | =1.0.6 | |
VMware Workstation | =5.5.0 | |
VMware Workstation | =5.5.1 | |
VMware Workstation | =5.5.2 | |
VMware Workstation | =5.5.3 | |
VMware Workstation | =5.5.4 | |
VMware Workstation | =5.5.5 | |
VMware Workstation | =5.5.6 | |
VMware Workstation | =5.5.7 | |
VMware Workstation | =5.5.8 | |
VMware Workstation | =6.0 | |
VMware Workstation | =6.0.1 | |
VMware Workstation | =6.0.2 | |
VMware Workstation | =6.0.3 | |
VMware Workstation | =6.0.4 | |
VMware Workstation | =6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-5438 is classified as high due to potential remote code execution capabilities.
To fix CVE-2007-5438, upgrade to VMware Workstation version 5.5.8 or higher, or the respective patched versions for VMware Player and ACE.
CVE-2007-5438 affects VMware Workstation 5.5.x before 5.5.8, VMware Player 1.x and 2.x before 2.0.5, and VMware ACE 1.x before 1.0.7.
Yes, CVE-2007-5438 can potentially be exploited remotely, allowing an attacker to execute arbitrary code.
There is no official workaround for CVE-2007-5438; applying the security updates is the recommended approach for mitigation.