First published: Mon Nov 10 2008(Updated: )
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ESXi | =3.5 | |
VMware Workstation | >=5.5<=5.5.8 | |
VMware Workstation | >=6.0<=6.0.5 | |
VMware Player | >=1.0.0<=1.0.8 | |
VMware Player | >=2.0<=2.0.5 | |
VMware ACE | >=1.0<=1.0.7 | |
VMware ACE | >=2.0<=2.0.5 | |
VMware Server | >=1.0<=1.0.7 | |
VMware ESX | >=2.5.4<=3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4915 is classified as a critical vulnerability affecting multiple VMware products.
To fix CVE-2008-4915, update your VMware software to the latest version available from VMware.
CVE-2008-4915 affects VMware Workstation 6.0.5 and earlier, Player 2.0.x through 2.0.5, and several other older VMware product versions.
CVE-2008-4915 is a CPU hardware emulation vulnerability that can be exploited by an attacker.
There are no known workarounds for CVE-2008-4915, so patching is the recommended course of action.