CVE-2014-4199: Medium severity VMware Tools vulnerability
Published Aug 28, 2014
·Updated
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
Affected Software
6 affected components
VMware Tools
VMware vm-support=0.88
VMware Workstation<=10.0.3
VMware Workstation=10.0
VMware Workstation=10.0.1
VMware Workstation=10.0.2
Event History
Aug 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4199?
CVE-2014-4199 is considered a medium severity vulnerability due to its local exploitation potential.
2
How do I fix CVE-2014-4199?
To fix CVE-2014-4199, upgrade to a version of VMware Tools or VMware Workstation that is later than the affected versions.
3
Who is affected by CVE-2014-4199?
Local users of VMware Tools version 0.88 and VMware Workstation up to 10.0.3 are affected by CVE-2014-4199.
4
What type of attack is associated with CVE-2014-4199?
CVE-2014-4199 is associated with a symlink attack that allows local users to write to arbitrary files.
5
Can CVE-2014-4199 be exploited remotely?
No, CVE-2014-4199 requires local access to the system in order to be exploited.