CVE-2009-3732: Critical severity VMware ACE vulnerability
Published Apr 12, 2010
·Updated
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
16 affected components
VMware ACE>=2.5.0<2.5.4
VMware ACE=2.6
VMware Player>=2.5.0<2.5.4
VMware Player=3.0
VMware Server>=2.0.0<=2.0.2
VMware Workstation>=6.5.0<6.5.4
VMware Workstation=7.0
Microsoft Windows
All of the following
Any of the following
VMware ACE>=2.5.0<2.5.4
VMware ACE=2.6
VMware Player>=2.5.0<2.5.4
VMware Player=3.0
VMware Server>=2.0.0<=2.0.2
VMware Workstation>=6.5.0<6.5.4
VMware Workstation=7.0
Microsoft Windows
Remediation
Event History
Apr 12, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3732?
CVE-2009-3732 has a high severity rating as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2009-3732?
To fix CVE-2009-3732, update your VMware software to the latest version provided by VMware.
3
Which software versions are affected by CVE-2009-3732?
CVE-2009-3732 affects multiple VMware products including VMware ACE, Player, Server, and Workstation from specific versions.
4
Can CVE-2009-3732 be exploited remotely?
Yes, CVE-2009-3732 is a remote code execution vulnerability that can be exploited by attackers from a distance.
5
Are there any known exploits for CVE-2009-3732?
Yes, there are known exploit vectors for CVE-2009-3732 that attackers can use to leverage this vulnerability.