CVE-2013-5973: Medium severity vmware esxi vulnerability
VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5973?
CVE-2013-5973 is rated as a moderate severity vulnerability.
How do I fix CVE-2013-5973?
To fix CVE-2013-5973, upgrade to a patched version of VMware ESXi or ESX that resolves this issue.
What environments are affected by CVE-2013-5973?
CVE-2013-5973 affects VMware ESXi versions 4.0 through 5.5 and ESX versions 4.0 and 4.1.
What types of files can be accessed using CVE-2013-5973?
CVE-2013-5973 allows local users to read or modify arbitrary files including those with -flat, -rdm, or -rdmp filenames.
Who can exploit CVE-2013-5973?
CVE-2013-5973 can be exploited by local users with the Virtual Machine Power User or Resource Pool Administrator role.