CVE-2017-16873: High severity HashiCorp Vagrant VMware Fusion vulnerability
Published Mar 29, 2018
·Updated
It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to root privileges.
Affected Software
1 affected component
HashiCorp Vagrant VMware Fusion>=4.0.25<=5.0.4
Event History
Mar 29, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16873?
CVE-2017-16873 is classified as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2017-16873?
To mitigate CVE-2017-16873, update Vagrant VMware Fusion to version 5.0.5 or later.
3
What are the potential impacts of CVE-2017-16873?
The exploitation of CVE-2017-16873 could allow attackers to achieve root access on affected systems.
4
Which software versions are affected by CVE-2017-16873?
CVE-2017-16873 affects Vagrant VMware Fusion versions 4.0.25 through 5.0.4.
5
Is CVE-2017-16873 specific to certain operating systems?
CVE-2017-16873 is primarily relevant to systems using the vulnerable versions of Vagrant VMware Fusion.