CVE-2008-1363: High severity microsoft windows operating system vulnerability
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1363?
CVE-2008-1363 is classified as a moderate severity vulnerability allowing local users to gain privileges.
How do I fix CVE-2008-1363?
To address CVE-2008-1363, upgrade VMware Workstation to version 6.0.3, Player to version 2.0.3, ACE to version 2.0.1, or Server to version 1.0.5 or later.
Which VMware products are affected by CVE-2008-1363?
CVE-2008-1363 affects VMware Workstation 6.0.x before 6.0.3, 5.5.x before 5.5.6, Player 2.0.x before 2.0.3, ACE 2.0.x before 2.0.1, and Server 1.0.x before 1.0.5.
Can CVE-2008-1363 be exploited remotely?
No, CVE-2008-1363 can only be exploited locally by users with access to the affected VMware applications.
What type of attack does CVE-2008-1363 facilitate?
CVE-2008-1363 facilitates privilege escalation, allowing local users to gain elevated privileges within the VMware environment.