CVE-2017-11741
Hashicorp vagrant-vmware-fusion 4.0.23 - Local Privilege Escalation
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.
El plugin HashiCorp Vagrant VMware Fusion (también conocido como vagrant-vmware-fusion) en sus versiones anteriores a la 4.0.24 utiliza permisos débiles para los scripts sudo helper, permitiendo que usuarios locales ejecuten código arbitrario con privilegios root sobreescribiendo uno de los scripts.
Hashicorp vagrant-vmware-fusion versions 4.0.23 and below suffer from a local privilege escalation vulnerability.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-07-29 CVE Reserved
- 2017-08-03 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2017/Aug/0 | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/43224 | 2024-08-05 | |
https://m4.rkw.io/blog/cve201711741-local-root-privesc-in-hashicorp-vagrantvmwarefusion--4023.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hashicorp Search vendor "Hashicorp" | Vagrant Vmware Fusion Search vendor "Hashicorp" for product "Vagrant Vmware Fusion" | <= 4.0.23 Search vendor "Hashicorp" for product "Vagrant Vmware Fusion" and version " <= 4.0.23" | - |
Affected
|