// For flags

CVE-2008-0923

 

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.

Vulnerabilidad de salto de directorio en la característica de Archivos Compartidos de VMWare ACE 1.0.2 y 2.0.2, Player 1.0.4 y 2.0.2, y Workstation 5.5.4 y 6.0.2 permite a usuarios de SO invitados leer y escribir archivos de su elección en el SO anfitrión a través de una cadena multibyte que produce una cadena de caracteres ancha que contiene secuencias de .. (punto punto), lo que evita el mecanismo de protección, como se demostró usando una cadena "%c0%2e%c0%2e".

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-02-25 CVE Reserved
  • 2008-02-25 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (20)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Ace
Search vendor "Vmware" for product "Ace"
1.0
Search vendor "Vmware" for product "Ace" and version "1.0"
-
Affected
Vmware
Search vendor "Vmware"
Ace
Search vendor "Vmware" for product "Ace"
1.0.2
Search vendor "Vmware" for product "Ace" and version "1.0.2"
-
Affected
Vmware
Search vendor "Vmware"
Ace
Search vendor "Vmware" for product "Ace"
2.0
Search vendor "Vmware" for product "Ace" and version "2.0"
-
Affected
Vmware
Search vendor "Vmware"
Ace
Search vendor "Vmware" for product "Ace"
2.0.1
Search vendor "Vmware" for product "Ace" and version "2.0.1"
-
Affected
Vmware
Search vendor "Vmware"
Ace
Search vendor "Vmware" for product "Ace"
2.0.2
Search vendor "Vmware" for product "Ace" and version "2.0.2"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
1.0.4
Search vendor "Vmware" for product "Player" and version "1.0.4"
-
Affected
Vmware
Search vendor "Vmware"
Vmware Player
Search vendor "Vmware" for product "Vmware Player"
1.0.1_build_19317
Search vendor "Vmware" for product "Vmware Player" and version "1.0.1_build_19317"
-
Affected
Vmware
Search vendor "Vmware"
Vmware Player
Search vendor "Vmware" for product "Vmware Player"
1.0.2
Search vendor "Vmware" for product "Vmware Player" and version "1.0.2"
-
Affected
Vmware
Search vendor "Vmware"
Vmware Player
Search vendor "Vmware" for product "Vmware Player"
1.0.3
Search vendor "Vmware" for product "Vmware Player" and version "1.0.3"
-
Affected
Vmware
Search vendor "Vmware"
Vmware Workstation
Search vendor "Vmware" for product "Vmware Workstation"
6.0.1
Search vendor "Vmware" for product "Vmware Workstation" and version "6.0.1"
-
Affected
Vmware
Search vendor "Vmware"
Vmware Workstation
Search vendor "Vmware" for product "Vmware Workstation"
6.0.2
Search vendor "Vmware" for product "Vmware Workstation" and version "6.0.2"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
4.5.2
Search vendor "Vmware" for product "Workstation" and version "4.5.2"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
5.5.3_build_34685
Search vendor "Vmware" for product "Workstation" and version "5.5.3_build_34685"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
5.5.4
Search vendor "Vmware" for product "Workstation" and version "5.5.4"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
6.0
Search vendor "Vmware" for product "Workstation" and version "6.0"
-
Affected