First published: Thu Aug 28 2014(Updated: )
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open VM Tools | ||
VMware Support | =0.88 | |
VMware Workstation and ESXi | <=10.0.3 | |
VMware Workstation and ESXi | =10.0 | |
VMware Workstation and ESXi | =10.0.1 | |
VMware Workstation and ESXi | =10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4199 is considered a medium severity vulnerability due to its local exploitation potential.
To fix CVE-2014-4199, upgrade to a version of VMware Tools or VMware Workstation that is later than the affected versions.
Local users of VMware Tools version 0.88 and VMware Workstation up to 10.0.3 are affected by CVE-2014-4199.
CVE-2014-4199 is associated with a symlink attack that allows local users to write to arbitrary files.
No, CVE-2014-4199 requires local access to the system in order to be exploited.