VMware Workstation 10.x < 10.0.7 / 11.x < 11.1.1 DACL Privilege Escalation (VMSA-2015-0005)
High Nessus Plugin ID 84806
SynopsisThe virtualization application installed on the remote host is affected by a privilege escalation vulnerability.
DescriptionThe version of VMware Workstation installed on the remote host is 10.x prior to 10.0.7 or 11.x prior to 11.1.1. It is, therefore, affected by a privilege escalation vulnerability due to a failure to provide a valid discretionary access control list (DACL) pointer for the printproxy.exe process. A local attacker, using thread injection, can exploit this to gain elevated privileges or execute arbitrary code.
SolutionUpgrade to VMware Workstation version 10.0.7 / 11.1.1 or later.