CVE-2013-1662: Medium severity vmware workstation and esxi vulnerability
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsbrelease binary in a directory in the PATH, related to use of the popen library function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1662?
CVE-2013-1662 has been classified as a moderate vulnerability, allowing privilege escalation on affected systems.
How do I fix CVE-2013-1662?
To mitigate CVE-2013-1662, you should update your VMware Workstation or Player to the latest version that contains the security patches.
Which versions of VMware are affected by CVE-2013-1662?
CVE-2013-1662 affects VMware Workstation 8.x and 9.x, as well as VMware Player 4.x and 5.x on Debian GNU/Linux systems.
What kind of exploitation is possible with CVE-2013-1662?
CVE-2013-1662 allows local users to gain host OS privileges through a crafted lsb_release binary.
Is there a workaround for CVE-2013-1662?
A potential workaround for CVE-2013-1662 is to remove or restrict permissions on the lsb_release binary in the PATH.