First published: Fri Oct 07 2011(Updated: )
Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation and ESXi | =7.1.3 | |
VMware Workstation and ESXi | =7.0 | |
VMware Workstation and ESXi | =7.0.1 | |
VMware Workstation and ESXi | =7.1 | |
VMware Workstation and ESXi | =7.1.1 | |
VMware Workstation and ESXi | =7.1.4 | |
VMware Workstation and ESXi | =7.1.2 | |
VMware Player | =3.0.1 | |
VMware Player | =3.0 | |
VMware Player | =3.1.2 | |
VMware Player | =3.1 | |
VMware Player | =3.1.3 | |
VMware Player | =3.1.1 | |
VMware Player | =3.1.4 | |
VMware Fusion | =3.1.2 | |
VMware Fusion | =3.1 | |
VMware Fusion | =3.1.1 | |
VMware vRealize Operations Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3868 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2011-3868, upgrade your VMware Workstation, Player, or Fusion to the latest versions that are not affected.
CVE-2011-3868 affects VMware Workstation versions prior to 7.1.5, Player versions prior to 3.1.5, and Fusion versions prior to 3.1.3.
Exploiting CVE-2011-3868 allows remote attackers to execute arbitrary code via a malicious UDF filesystem in an ISO image.
Yes, patches are available in the latest updates of VMware Workstation, Player, and Fusion that resolve CVE-2011-3868.