CVE-2007-4155
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first two arguments to the (1) CreateProcess or (2) CreateProcessEx method.
Vulnerabilidad de salto de ruta absoluta en un determinado control ActiveX en vielib.dll de EMC VMware 6.0.0 permite a atacantes remotos ejecutar programas locales de su elección mediante un nombre de ruta absoluta en los dos primeros argumentos de los métodos (1) CreateProcess ó (2) CreateProcessEx
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-08-03 CVE Reserved
- 2007-08-03 CVE Published
- 2024-06-06 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html | Mailing List | |
http://secunia.com/advisories/26890 | Third Party Advisory | |
http://www.securityfocus.com/bid/25131 | Vdb Entry | |
http://www.securitytracker.com/id?1018511 | Vdb Entry | |
http://www.vmware.com/support/ace/doc/releasenotes_ace.html | X_refsource_confirm | |
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html | X_refsource_confirm | |
http://www.vmware.com/support/player/doc/releasenotes_player.html | X_refsource_confirm | |
http://www.vmware.com/support/player2/doc/releasenotes_player2.html | X_refsource_confirm | |
http://www.vmware.com/support/server/doc/releasenotes_server.html | X_refsource_confirm | |
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html | X_refsource_confirm | |
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html | X_refsource_confirm | |
http://www.vupen.com/english/advisories/2007/3229 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35670 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/4245 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|