CVE-2007-5438: Input Validation
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 might allow local users to cause a denial of service to the Virtual Disk Mount Service (vmount2.exe), related to the ConnectPopulatedDiskEx function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5438?
The severity of CVE-2007-5438 is classified as high due to potential remote code execution capabilities.
How do I fix CVE-2007-5438?
To fix CVE-2007-5438, upgrade to VMware Workstation version 5.5.8 or higher, or the respective patched versions for VMware Player and ACE.
What versions of VMware are affected by CVE-2007-5438?
CVE-2007-5438 affects VMware Workstation 5.5.x before 5.5.8, VMware Player 1.x and 2.x before 2.0.5, and VMware ACE 1.x before 1.0.7.
Can CVE-2007-5438 be exploited remotely?
Yes, CVE-2007-5438 can potentially be exploited remotely, allowing an attacker to execute arbitrary code.
Is there a workaround for CVE-2007-5438?
There is no official workaround for CVE-2007-5438; applying the security updates is the recommended approach for mitigation.