First published: Tue Jan 20 2009(Updated: )
vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ACE | <=2.5.1 | |
VMware Player | =1.0.3 | |
VMware Player | =1.0.7 | |
VMware Player | =1.0.8 | |
VMware Player | =2.0.3 | |
VMware Player | <=2.5.1 | |
VMware VMware Workstation | =6.0.5 | |
VMware Player | =1.0.9 | |
VMware Player | =1.0.2 | |
VMware VMware Workstation | =5.5.6 | |
VMware Server | =2.0.0 | |
VMware Player | =2.0.2 | |
VMware VMware Workstation | =6.0 | |
VMware VMware Workstation | =5.5.3 | |
VMware VMware Workstation | =6.5 | |
VMware Player | =1.0.0 | |
VMware VMware Workstation | =5.5.5 | |
VMware Player | =2.0.4 | |
VMware Player | =1.05 | |
VMware VMware Workstation | =5.5.0 | |
VMware Player | =2.5 | |
VMware VMware Workstation | =6.0.4 | |
VMware VMware Workstation | =5.5.7 | |
VMware VMware Workstation | =4.5.3 | |
VMware VMware Workstation | =6.0.2 | |
VMware Player | =1.0.6 | |
VMware Player | =2.0.1 | |
VMware VMware Workstation | =5.5.2 | |
VMware Player | =1.0.1 | |
VMware VMware Workstation | =5.0 | |
VMware VMware Workstation | <=6.51 | |
VMware ACE | =2.5.0 | |
VMware Fusion Pro | <=2.0.1 | |
VMware Player | =1.0.4 | |
VMware VMware Workstation | =5.5.8 | |
VMware VMware Workstation | =6.0.3 | |
VMware VMware Workstation | =6.0.1 | |
VMware Player | =2.0.5 | |
VMware Player | =2.0 | |
VMware VMware Workstation | =5.5.1 | |
VMware VMware Workstation | =5.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-0177 is classified as critical due to potential remote code execution vulnerabilities.
To fix CVE-2009-0177, upgrade to a patched version of VMware Workstation, Player, ACE, Server, or Fusion as advised by VMware.
CVE-2009-0177 affects VMware Workstation versions 6.5.1 and earlier, VMware Player versions 2.5.1 and earlier, and several specific versions of VMware ACE and Server.
Yes, CVE-2009-0177 is considered widespread as it affects multiple VMware products and versions used by many organizations.
CVE-2009-0177 can be exploited by attackers to execute arbitrary code on affected systems, potentially leading to unauthorized access and data breaches.