CVE-2007-5023

high

Description

Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder.

References

http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html

http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html

http://www.vmware.com/support/server/doc/releasenotes_server.html

http://www.vmware.com/support/player2/doc/releasenotes_player2.html

http://www.vmware.com/support/player/doc/releasenotes_player.html

http://www.vmware.com/support/ace/doc/releasenotes_ace.html

http://www.securityfocus.com/bid/25732

Details

Source: Mitre, NVD

Published: 2007-09-21

Updated: 2019-08-01

Risk Information

CVSS v2

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High