CVE-2012-4897: Medium severity VMware Movie Decoder vulnerability
Published Oct 5, 2012
·Updated
Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
Affected Software
6 affected components
VMware Movie Decoder<=7.1.2
VMware Movie Decoder=6.5.2
VMware Movie Decoder=6.5.3
VMware Movie Decoder=6.5.4
VMware Movie Decoder=6.5.5
VMware Movie Decoder=7.0
Event History
Oct 5, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4897?
CVE-2012-4897 is classified with high severity due to its potential for privilege escalation.
2
How do I fix CVE-2012-4897?
To fix CVE-2012-4897, it is recommended to update VMware Movie Decoder to version 9.0 or later.
3
Who is affected by CVE-2012-4897?
Local users with access to install VMware Movie Decoder versions prior to 9.0 are affected by CVE-2012-4897.
4
What type of vulnerability is CVE-2012-4897?
CVE-2012-4897 is an untrusted search path vulnerability affecting the installer of VMware Movie Decoder.
5
Can CVE-2012-4897 be exploited remotely?
CVE-2012-4897 cannot be exploited remotely; it requires local user access.