// For flags

CVE-2010-4297

VMware Tools - Update OS Command Injection

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS users to gain privileges on the guest OS via unspecified vectors, related to a "command injection" issue.

La funcionalidad actualizar de VMware Tools en VMware Workstation 6.5.x anteriores a la 6.5.5 build 328052 y 7.x anteriores a la 7.1.2 build 301548; VMware Player 2.5.x anteriores a la 2.5.5 build 328052 y 3.1.x anteriores a la 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x anteriores a la 2.0.8 build 328035 y 3.1.x anteriores a la 3.1.2 build 332101; VMware ESXi 3.5, 4.0, y 4.1; y VMware ESX 3.0.3, 3.5, 4.0, y 4.1 permite a los usuarios del SO base escalar privilegios en el SO invitado a través de vectores sin especificar. Relacionado con inyecciones de comandos.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-11-18 CVE Reserved
  • 2010-12-06 CVE Published
  • 2010-12-09 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
6.5.0
Search vendor "Vmware" for product "Workstation" and version "6.5.0"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
6.5.1
Search vendor "Vmware" for product "Workstation" and version "6.5.1"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
6.5.2
Search vendor "Vmware" for product "Workstation" and version "6.5.2"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
6.5.3
Search vendor "Vmware" for product "Workstation" and version "6.5.3"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
6.5.5
Search vendor "Vmware" for product "Workstation" and version "6.5.5"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
7.0
Search vendor "Vmware" for product "Workstation" and version "7.0"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
7.0.1
Search vendor "Vmware" for product "Workstation" and version "7.0.1"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
7.1
Search vendor "Vmware" for product "Workstation" and version "7.1"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
7.1.1
Search vendor "Vmware" for product "Workstation" and version "7.1.1"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
7.1.2
Search vendor "Vmware" for product "Workstation" and version "7.1.2"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
2.5
Search vendor "Vmware" for product "Player" and version "2.5"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
2.5.1
Search vendor "Vmware" for product "Player" and version "2.5.1"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
2.5.2
Search vendor "Vmware" for product "Player" and version "2.5.2"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
2.5.3
Search vendor "Vmware" for product "Player" and version "2.5.3"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
2.5.4
Search vendor "Vmware" for product "Player" and version "2.5.4"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
2.5.5
Search vendor "Vmware" for product "Player" and version "2.5.5"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
3.1
Search vendor "Vmware" for product "Player" and version "3.1"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
3.1.1
Search vendor "Vmware" for product "Player" and version "3.1.1"
-
Affected
Vmware
Search vendor "Vmware"
Player
Search vendor "Vmware" for product "Player"
3.1.2
Search vendor "Vmware" for product "Player" and version "3.1.2"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0
Search vendor "Vmware" for product "Fusion" and version "2.0"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.1
Search vendor "Vmware" for product "Fusion" and version "2.0.1"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.2
Search vendor "Vmware" for product "Fusion" and version "2.0.2"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.3
Search vendor "Vmware" for product "Fusion" and version "2.0.3"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.4
Search vendor "Vmware" for product "Fusion" and version "2.0.4"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.5
Search vendor "Vmware" for product "Fusion" and version "2.0.5"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.6
Search vendor "Vmware" for product "Fusion" and version "2.0.6"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.7
Search vendor "Vmware" for product "Fusion" and version "2.0.7"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
2.0.8
Search vendor "Vmware" for product "Fusion" and version "2.0.8"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
3.1
Search vendor "Vmware" for product "Fusion" and version "3.1"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
3.1.1
Search vendor "Vmware" for product "Fusion" and version "3.1.1"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
3.1.2
Search vendor "Vmware" for product "Fusion" and version "3.1.2"
-
Affected
Vmware
Search vendor "Vmware"
Server
Search vendor "Vmware" for product "Server"
2.0.2
Search vendor "Vmware" for product "Server" and version "2.0.2"
-
Safe
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
3.5
Search vendor "Vmware" for product "Esxi" and version "3.5"
-
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
4.0
Search vendor "Vmware" for product "Esxi" and version "4.0"
-
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
4.1
Search vendor "Vmware" for product "Esxi" and version "4.1"
-
Affected
Vmware
Search vendor "Vmware"
Esx
Search vendor "Vmware" for product "Esx"
3.5
Search vendor "Vmware" for product "Esx" and version "3.5"
-
Affected
Vmware
Search vendor "Vmware"
Esx
Search vendor "Vmware" for product "Esx"
4.0
Search vendor "Vmware" for product "Esx" and version "4.0"
-
Affected
Vmware
Search vendor "Vmware"
Esx
Search vendor "Vmware" for product "Esx"
4.1
Search vendor "Vmware" for product "Esx" and version "4.1"
-
Affected