CVE-2014-1208: Low severity VMware ESXi vulnerability
VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1208?
CVE-2014-1208 has a medium severity level due to its impact on system availability.
How do I fix CVE-2014-1208?
To fix CVE-2014-1208, upgrade VMware Workstation, Player, Fusion, or ESXi to the latest version as specified in the vendor's advisories.
What types of systems are affected by CVE-2014-1208?
CVE-2014-1208 affects VMware Workstation 9.x, VMware Player 5.x, VMware Fusion 5.x, VMware ESXi versions 4.0 to 5.1, and VMware ESX versions 4.0 and 4.1.
What attack vector can exploit CVE-2014-1208?
CVE-2014-1208 can be exploited through a denial of service attack by sending an invalid port command from guest OS users.
Is there a workaround for CVE-2014-1208?
There are no recommended workarounds for CVE-2014-1208; applying the vendor patches is the best course of action.