VMware Player Multiple Vulnerabilities (VMSA-2012-0009)

high Nessus Plugin ID 59091

Synopsis

The remote host has a virtualization application affected by multiple vulnerabilities.

Description

The VMware Player install detected on the remote host is 3.x earlier than 3.1.6, or 4.0.x earlier than 4.0.3 and is, therefore, potentially affected by the following vulnerabilities :

- Memory corruption errors exist related to the RPC commands handler function which could cause the application to crash or possibly allow an attacker to execute arbitrary code. Note that these errors only affect the 3.x branch. (CVE-2012-1516, CVE-2012-1517)

- An error in the virtual floppy device configuration can allow out-of-bounds memory writes and can allow a guest user to crash the VMX process or potentially execute arbitrary code on the host. Note that root or administrator level privileges in the guest are required for successful exploitation along with the existence of a virtual floppy device in the guest. (CVE-2012-2449)

- An error in the virtual SCSI device registration process can allow improper memory writes and can allow a guest user to crash the VMX process or potentially execute arbitrary code on the host. Note that root or administrator level privileges are required in the guest for successful exploitation along with the existence of a virtual SCSI device in the guest.
(CVE-2012-2450)

Solution

Upgrade to VMware Player 3.1.6 / 4.0.3 or later.

See Also

http://www.vmware.com/security/advisories/VMSA-2012-0009.html

http://lists.vmware.com/pipermail/security-announce/2012/000176.html

http://www.nessus.org/u?acb1cf3a

http://www.nessus.org/u?258456c3

Plugin Details

Severity: High

ID: 59091

File Name: vmware_player_multiple_vmsa_2012_0009.nasl

Version: 1.6

Type: local

Agent: windows

Family: Windows

Published: 5/15/2012

Updated: 12/4/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:vmware:player

Required KB Items: SMB/Registry/Enumerated, VMware/Player/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/13/2011

Vulnerability Publication Date: 5/3/2011

Reference Information

CVE: CVE-2012-1516, CVE-2012-1517, CVE-2012-2449, CVE-2012-2450

BID: 53369

VMSA: 2012-0009