First published: Thu Dec 11 2014(Updated: )
The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain privileges via vectors involving the "Connect (by) Using VMRC" function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCloud Automation Center | =6.0.1 | |
VMware vCloud Automation Center | =6.0.1.1 | |
VMware vCloud Automation Center | =6.0.1.2 | |
VMware vCloud Automation Center | =6.1 | |
VMware vCloud Automation Center | =6.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8373 has a medium severity rating due to its allowance for privilege escalation for authenticated users.
To address CVE-2014-8373, it is recommended to upgrade VMware vCloud Automation Center to version 6.1.2 or later.
CVE-2014-8373 is a privilege escalation vulnerability affecting the VMware Remote Console functionality.
Remote authenticated users of VMware vCloud Automation Center versions 6.0.1 to 6.1.1 are impacted by CVE-2014-8373.
CVE-2014-8373 was disclosed in December 2014, following security advisories regarding its impact.