First published: Mon Jun 06 2011(Updated: )
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation | =7.1.1 | |
VMware Workstation | =7.1.2 | |
VMware Workstation | =7.1.3 | |
VMware Player | =3.1 | |
VMware Player | =3.1.1 | |
VMware Player | =3.1.2 | |
VMware Player | =3.1.3 | |
VMware Fusion Pro | =3.1 | |
VMware Fusion Pro | =3.1.1 | |
VMware Fusion Pro | =3.1.2 | |
VMware ESX | =3.0.3 | |
VMware ESX | =3.5 | |
VMware ESX | =4.0 | |
VMware ESX | =4.1 | |
VMware ESXi | =3.5 | |
VMware ESXi | =4.0 | |
VMware ESXi | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1787 is considered a medium-severity vulnerability that allows guest OS users to gain elevated privileges.
The recommended fix for CVE-2011-1787 is to upgrade to VMware Workstation 7.1.4, Player 3.1.4, Fusion 3.1.3, or later versions.
CVE-2011-1787 affects VMware Workstation versions prior to 7.1.4, Player prior to 3.1.4, and Fusion prior to 3.1.3, as well as ESXi and ESX versions through 4.1.
CVE-2011-1787 cannot be exploited remotely as it requires local access to the guest OS.
CVE-2011-1787 impacts systems running VMware Workstation, VMware Player, VMware Fusion, and VMware ESX/ESXi.