First published: Tue Aug 01 2017(Updated: )
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4921 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
To fix CVE-2017-4921, upgrade VMware vCenter Server to version 6.5 U1 or later.
CVE-2017-4921 affects VMware vCenter Server version 6.5 prior to 6.5 U1.
Exploitation of CVE-2017-4921 can lead to unauthorized privilege escalation by unprivileged host users.
CVE-2017-4921 is a local privilege escalation vulnerability.