VMware ESXi Tools Guest OS Privilege Escalation (VMSA-2014-0005)

Medium Nessus Plugin ID 87677


The remote VMware ESXi host is missing a security-related patch.


The remote VMware ESXi host is affected by a privilege escalation vulnerability due to a NULL pointer dereference flaw in VMware Tools running on Microsoft Windows 8.1. An attacker on an adjacent network can exploit this issue to gain elevated privileges within the guest operating system or else cause the guest operating system to crash.


Apply the appropriate patch according to the vendor advisory that pertains to ESXi version 5.0 / 5.1 / 5.5.

See Also



Plugin Details

Severity: Medium

ID: 87677

File Name: vmware_VMSA-2014-0005_remote.nasl

Version: $Revision: 1.3 $

Type: remote

Family: Misc.

Published: 2015/12/30

Modified: 2016/01/06

Dependencies: 57396

Risk Information

Risk Factor: Medium


Base Score: 5.8

Temporal Score: 5

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:vmware:esxi:5.0, cpe:/o:vmware:esxi:5.1, cpe:/o:vmware:esxi:5.5

Required KB Items: Host/VMware/version, Host/VMware/release

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/05/29

Vulnerability Publication Date: 2014/05/29

Reference Information

CVE: CVE-2014-3793

BID: 67737

OSVDB: 107561

VMSA: 2014-0005