First published: Thu Mar 20 2008(Updated: )
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecurely created named pipe," a different vulnerability than CVE-2008-1361.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ACE | =1.0 | |
VMware Player | =2.0.1 | |
VMware Player | =2.0.2 | |
VMware Player | =1.0.2 | |
VMware ACE | =2.0 | |
VMware Workstation | =5.5.4_build_44386 | |
VMware Workstation | =6.0 | |
VMware Workstation | =5.5.3_build_34685 | |
VMware VMware Workstation | =5.5.5 | |
VMware Player | =1.0.3 | |
VMware Workstation | =5.5.3_build_42958 | |
VMware Workstation | =5.5 | |
VMware Server | =1.0.4 | |
VMware Player | =1.0.4 | |
VMware VMware Workstation | =6.0.2 | |
VMware Player | =1.0.5 | |
VMware Server | =1.0.3 | |
VMware Server | =1.0.2 | |
VMware Player | =2.0 | |
VMware VMware Workstation | =6.0.1 | |
VMware Workstation | =5.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1362 is categorized as critical due to its potential to allow local users to gain elevated privileges or cause a denial of service.
To fix CVE-2008-1362, users should upgrade to the latest versions of VMware Workstation 6.0.3, 5.5.6, VMware Player 2.0.3, 1.0.6, or apply patches provided by VMware.
CVE-2008-1362 affects VMware Workstation versions 6.0.x and 5.5.x, VMware Player versions 2.0.x and 1.0.x, VMware ACE versions 2.0.x and 1.0.x, and VMware Server version 1.0.x.
Local users can exploit CVE-2008-1362 to gain unauthorized privileges or impact system availability.
CVE-2008-1362 represents a local privilege escalation vulnerability in certain VMware products.