VMware Player 6.x < 6.0.7 / 7.x < 7.1.1 DACL Privilege Escalation (VMSA-2015-0005)
High Nessus Plugin ID 84805
SynopsisThe virtualization application installed on the remote host is affected by a privilege escalation vulnerability.
DescriptionThe version of VMware Player installed on the remote host is 6.x prior to 6.0.7 or 7.x prior to 7.1.1. It is, therefore, affected by a privilege escalation vulnerability due to a failure to provide a valid discretionary access control list (DACL) pointer for the printproxy.exe process. A local attacker, using thread injection, can exploit this to gain elevated privileges or execute arbitrary code.
SolutionUpgrade to VMware Player 6.0.7 / 7.1.1 or later.