CVE-2015-2342

high

Description

The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

References

http://seclists.org/fulldisclosure/2015/Oct/1

http://www.securityfocus.com/bid/76930

http://www.securitytracker.com/id/1033720

http://www.vmware.com/security/advisories/VMSA-2015-0007.html

http://www.zerodayinitiative.com/advisories/ZDI-15-455

https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/

Details

Source: MITRE

Published: 2015-10-12

Updated: 2018-08-12

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH