CVE-2014-4200: Medium severity VMware Tools vulnerability
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4200?
CVE-2014-4200 has a medium severity rating due to its potential to expose sensitive information to local users.
How do I fix CVE-2014-4200?
To fix CVE-2014-4200, update VMware Tools and VMware Workstation to the most recent versions.
What does CVE-2014-4200 affect?
CVE-2014-4200 affects VMware Tools version 0.88 and VMware Workstation versions up to and including 10.0.3.
What type of vulnerability is CVE-2014-4200?
CVE-2014-4200 is a local information disclosure vulnerability due to improper file permissions.
Who is impacted by CVE-2014-4200?
Local users on systems with vulnerable versions of VMware Tools or VMware Workstation are impacted by CVE-2014-4200.