First published: Thu Mar 29 2018(Updated: )
It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to root privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vagrant | >=4.0.25<=5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16873 is classified as a high severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2017-16873, update Vagrant VMware Fusion to version 5.0.5 or later.
The exploitation of CVE-2017-16873 could allow attackers to achieve root access on affected systems.
CVE-2017-16873 affects Vagrant VMware Fusion versions 4.0.25 through 5.0.4.
CVE-2017-16873 is primarily relevant to systems using the vulnerable versions of Vagrant VMware Fusion.