First published: Tue Aug 08 2017(Updated: )
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vagrant | <=4.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11741 has a critical severity level as it allows local users to execute arbitrary code with root privileges.
To fix CVE-2017-11741, upgrade the Vagrant VMware Fusion plugin to version 4.0.24 or later.
Users of HashiCorp Vagrant VMware Fusion versions prior to 4.0.24 are affected by CVE-2017-11741.
CVE-2017-11741 is classified as a local privilege escalation vulnerability.
No, CVE-2017-11741 requires local user access to exploit the vulnerability.