CVE-2017-4922: Infoleak
Published Aug 1, 2017
·Updated
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
Affected Software
1 affected component
VMware vCenter Server=6.5
Remediation
Event History
Aug 1, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-4922?
CVE-2017-4922 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-4922?
To fix CVE-2017-4922, upgrade VMware vCenter Server to version 6.5 U1 or later.
3
What type of vulnerability is CVE-2017-4922?
CVE-2017-4922 is an information disclosure vulnerability.
4
Who is affected by CVE-2017-4922?
CVE-2017-4922 affects VMware vCenter Server 6.5 prior to 6.5 U1.
5
What can attackers gain from exploiting CVE-2017-4922?
Successful exploitation of CVE-2017-4922 may allow unprivileged host users to access critical information.