CVE-2009-0908: Medium severity VMware ACE vulnerability

Published Apr 6, 2009
·
Updated

Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder.

Affected Software

17 affected components
VMware ACE<=2.5.1
VMware ACE=1.0
VMware ACE=1.0.0
VMware ACE=1.0.1
VMware ACE=1.0.2
VMware ACE=1.0.3
VMware ACE=1.0.4
VMware ACE=1.0.5
VMware ACE=1.0.6
VMware ACE=1.0.7
VMware ACE=2.0
VMware ACE=2.0.1
VMware ACE=2.0.2
VMware ACE=2.0.3
VMware ACE=2.0.4
VMware ACE=2.0.5
VMware ACE=2.5.0

Event History

Apr 6, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:30 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2009-0908?

CVE-2009-0908 is considered a moderate severity vulnerability due to the potential for unauthorized access to shared folders.

2

How do I fix CVE-2009-0908?

To remediate CVE-2009-0908, ensure that you upgrade to VMware ACE version 2.5.1 or later where the vulnerability is patched.

3

What systems are affected by CVE-2009-0908?

CVE-2009-0908 affects VMware ACE versions 2.5.1 and earlier, including versions 1.0 and 2.0.x.

4

What is the impact of CVE-2009-0908?

The impact of CVE-2009-0908 allows attackers to enable previously disabled shared folders, potentially leading to data exposure.

5

Is there a workaround for CVE-2009-0908?

A temporary workaround for CVE-2009-0908 is to disable the use of shared folders until a patch can be applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203