CVE-2007-5671: Input Validation
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHODNEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5671?
CVE-2007-5671 has been classified as a moderate severity vulnerability due to potential unauthorized access risks.
How do I fix CVE-2007-5671?
To fix CVE-2007-5671, update to the latest version of VMware Tools and ensure your VMware software is at least VMware Workstation 5.5.6, VMware Player 1.0.6, or VMware Server 1.0.5.
Which VMware products are affected by CVE-2007-5671?
CVE-2007-5671 affects VMware Workstation 5.x versions prior to 5.5.6, VMware Player versions prior to 1.0.6, VMware ACE versions prior to 1.0.5, and VMware Server versions prior to 1.0.5, as well as VMware ESX 2.5.4 through 3.0.2.
What type of vulnerability is CVE-2007-5671?
CVE-2007-5671 is a user-mode vulnerability related to improper argument validation in the HGFS.sys component of VMware.
Is there a workaround for CVE-2007-5671?
The best workaround for CVE-2007-5671 is to disable VMware Tools or avoid using programs that utilize HGFS functionality until the software is updated.