CVE-2017-12579: High severity HashiCorp Vagrant VMware Fusion vulnerability
Published Oct 19, 2017
·Updated
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.
Affected Software
1 affected component
HashiCorp Vagrant VMware Fusion<=4.0.24
Event History
Oct 19, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12579?
CVE-2017-12579 is considered to have a high severity rating due to its potential to allow non-root users to gain root access.
2
How do I fix CVE-2017-12579?
To fix CVE-2017-12579, update the HashiCorp Vagrant VMware Fusion plugin to version 4.0.25 or later.
3
What can attackers do with CVE-2017-12579?
Attackers can exploit CVE-2017-12579 to obtain a root shell on the affected system.
4
Which versions of HashiCorp Vagrant VMware Fusion are affected by CVE-2017-12579?
CVE-2017-12579 affects HashiCorp Vagrant VMware Fusion versions up to and including 4.0.24.
5
Is CVE-2017-12579 remotely exploitable?
CVE-2017-12579 is not remotely exploitable; it requires local access to the affected system.