CVE-2010-4296: High severity vmware workstation and esxi vulnerability
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4296?
CVE-2010-4296 has a moderate severity rating due to its potential to escalate privileges for host OS users.
How do I fix CVE-2010-4296?
To fix CVE-2010-4296, upgrade VMware Workstation to version 7.1.2 or higher, VMware Player to version 3.1.2 or higher, VMware Server to version 2.0.2 or higher, or VMware Fusion to version 3.1.2 or higher.
Which VMware products are affected by CVE-2010-4296?
CVE-2010-4296 affects VMware Workstation versions 7.0 to 7.1.1, VMware Player versions 3.1 to 3.1.1, VMware Server 2.0.2, and VMware Fusion versions 3.1 to 3.1.1.
What platforms are impacted by CVE-2010-4296?
CVE-2010-4296 impacts VMware software running on Linux platforms.
Can CVE-2010-4296 be exploited remotely?
CVE-2010-4296 cannot be exploited remotely as it requires local access to the host operating system.