VMware ESXi Tools Guest OS Privilege Escalation (VMSA-2014-0005)

medium Nessus Plugin ID 87677

Synopsis

The remote VMware ESXi host is missing a security-related patch.

Description

The remote VMware ESXi host is affected by a privilege escalation vulnerability due to a NULL pointer dereference flaw in VMware Tools running on Microsoft Windows 8.1. An attacker on an adjacent network can exploit this issue to gain elevated privileges within the guest operating system or else cause the guest operating system to crash.

Solution

Apply the appropriate patch according to the vendor advisory that pertains to ESXi version 5.0 / 5.1 / 5.5.

See Also

https://www.vmware.com/security/advisories/VMSA-2014-0005

http://lists.vmware.com/pipermail/security-announce/2014/000247.html

Plugin Details

Severity: Medium

ID: 87677

File Name: vmware_VMSA-2014-0005_remote.nasl

Version: 1.5

Type: remote

Family: Misc.

Published: 12/30/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:vmware:esxi:5.0, cpe:/o:vmware:esxi:5.1, cpe:/o:vmware:esxi:5.5

Required KB Items: Host/VMware/release, Host/VMware/version

Exploit Ease: No known exploits are available

Patch Publication Date: 5/29/2014

Vulnerability Publication Date: 5/29/2014

Reference Information

CVE: CVE-2014-3793

BID: 67737

VMSA: 2014-0005