CVE-2009-3707: Medium severity vmware ace vulnerability
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3707?
The severity of CVE-2009-3707 is classified as a security vulnerability that could allow unauthorized access to the VMware Authentication Daemon.
How do I fix CVE-2009-3707?
To fix CVE-2009-3707, upgrade VMware Workstation to version 7.0.1 or later, or to VMware Player version 3.0.1 or later.
Which VMware products are affected by CVE-2009-3707?
CVE-2009-3707 affects VMware Workstation versions prior to 7.0.1, VMware Player versions prior to 3.0.1, and several versions of VMware ACE.
Can CVE-2009-3707 be exploited remotely?
Yes, CVE-2009-3707 can potentially be exploited remotely if the VMware services are exposed.
Is there a workaround for CVE-2009-3707?
A temporary workaround for CVE-2009-3707 is to restrict network access to the VMware services until an upgrade can be applied.