First published: Wed Nov 14 2012(Updated: )
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Player | =4.0 | |
VMware Player | =4.0.0.18997 | |
VMware Player | =4.0.1 | |
VMware Player | =4.0.2 | |
VMware Player | =4.0.3 | |
VMware Player | =4.0.4 | |
VMware Workstation | =8.0 | |
VMware Workstation | =8.0.0.18997 | |
VMware Workstation | =8.0.1 | |
VMware Workstation | =8.0.1.27038 | |
VMware Workstation | =8.0.2 | |
VMware Workstation | =8.0.3 | |
VMware Workstation | =8.0.4 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5459 is considered a moderate severity vulnerability allowing host OS users to gain elevated privileges.
To fix CVE-2012-5459, it is recommended to update VMware Workstation to version 8.0.5 or later, and VMware Player to version 4.0.5 or later.
CVE-2012-5459 affects VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows.
CVE-2012-5459 is an untrusted search path vulnerability that can be exploited via a Trojan horse DLL.
Failing to address CVE-2012-5459 could allow attackers to gain unauthorized host OS privileges, leading to potential system compromise.