CVE-2014-3790: Critical severity VMware vCenter Server Appliance vulnerability
Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3790?
CVE-2014-3790 has been rated as a critical vulnerability due to its potential for remote command execution as root.
How do I fix CVE-2014-3790?
To mitigate CVE-2014-3790, upgrade to a patched version of VMware vCenter Server Appliance that addresses the vulnerability.
Who is affected by CVE-2014-3790?
CVE-2014-3790 affects remote authenticated users of the Ruby vSphere Console in VMware vCenter Server Appliance versions 5.1 and 5.5.
What type of vulnerability is CVE-2014-3790?
CVE-2014-3790 is classified as a command injection vulnerability that allows unauthorized command execution.
What impact does CVE-2014-3790 have on security?
CVE-2014-3790 can lead to complete system compromise since it allows attackers to execute arbitrary commands with root privileges.