English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

VMware Multiple Products Privilege Escalation Security Issue


Secunia ID

SA48782

CVE-ID

CVE-2012-1518

Release Date

13 Apr 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Software

VMware Fusion 4.x
VMware Workstation 8.x

Where

Local system

Impact
Privilege escalation

This covers vulnerabilities where a user is able to conduct certain tasks with the privileges of other users or administrative users.

This typically includes cases where a local user on a client or server system can gain access to the administrator or root account thus taking full control of the system.

Description

A security issue has been reported in multiple VMware products, which can be exploited by malicious, local users to gain escalated privileges.

The security issue is caused due to the application setting insecure permissions on the VMware Tools folder and can be exploited to gain escalated privileges on Windows-based guest operating systems.

Please see the vendor's advisory for a list of affected products and versions.

Solution

Update to a fixed version (please see the vendor's advisory for details).

Reported by

The vendor credits Tavis Ormandy.

Original Advisory

VMware:
http://www.vmware.com/security/advisories/VMSA-2012-0007.html