VMware Fusion 5.x < 5.0.4 LGTOSYNC.SYS Privilege Escalation (VMSA-2013-0014)

High Nessus Plugin ID 71230

Synopsis

The remote host has a virtualization application that is affected by a privilege escalation vulnerability.

Description

The version of VMware Fusion 5.x installed on the remote Mac OS X host is prior to 5.0.4. It is, therefore, reportedly affected by a privilege escalation vulnerability in the LGTOSYNC.SYS driver on 32-bit Guest Operating Systems running Windows XP.

Note that by exploiting this issue, a local attacker could elevate his privileges only on the Guest Operating System and not on the host.

Solution

Upgrade to VMware Fusion 5.0.4 or later.

Plugin Details

Severity: High

ID: 71230

File Name: macosx_fusion_5_0_4.nasl

Version: 1.5

Type: local

Agent: macosx

Published: 2013/12/05

Updated: 2019/11/27

Dependencies: 50828

Risk Information

Risk Factor: High

CVSS Score Source: CVE-2013-3519

CVSS v2.0

Base Score: 7.9

Temporal Score: 5.8

Vector: CVSS2#AV:A/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:vmware:fusion

Required KB Items: Host/local_checks_enabled, MacOSX/Fusion/Version

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/11/14

Vulnerability Publication Date: 2013/12/03

Reference Information

CVE: CVE-2013-3519

BID: 64075

VMSA: 2013-0014