CVE-2017-11741: High severity HashiCorp Vagrant VMware Fusion vulnerability
Published Aug 8, 2017
·Updated
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.
Affected Software
1 affected component
HashiCorp Vagrant VMware Fusion<=4.0.23
Event History
Aug 8, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11741?
CVE-2017-11741 has a critical severity level as it allows local users to execute arbitrary code with root privileges.
2
How do I fix CVE-2017-11741?
To fix CVE-2017-11741, upgrade the Vagrant VMware Fusion plugin to version 4.0.24 or later.
3
Who is affected by CVE-2017-11741?
Users of HashiCorp Vagrant VMware Fusion versions prior to 4.0.24 are affected by CVE-2017-11741.
4
What type of vulnerability is CVE-2017-11741?
CVE-2017-11741 is classified as a local privilege escalation vulnerability.
5
Can CVE-2017-11741 be exploited remotely?
No, CVE-2017-11741 requires local user access to exploit the vulnerability.