VMSA-2016-0001 : VMware ESXi, Workstation, Player, and Fusion updates address important guest privilege escalation vulnerability
Medium Nessus Plugin ID 87889
SynopsisThe remote VMware ESXi host is missing a security-related patch.
DescriptionImportant Windows-based guest privilege escalation in VMware Tools
A kernel memory corruption vulnerability is present in the VMware Tools 'Shared Folders' (HGFS) feature running on Microsoft Windows. Successful exploitation of this issue could lead to an escalation of privilege in the guest operating system.
VMware would like to thank Dmitry Janushkevich from the Secunia Research Team for reporting this issue to us.
Note: This vulnerability does not allow for privilege escalation from the guest operating system to the host. Host memory can not be manipulated from the guest operating system by exploiting this flaw.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-6933 to this issue.
Workarounds Removing the 'Shared Folders' (HGFS) feature from previously installed VMware Tools will remove the possibility of exploitation.
SolutionApply the missing patch.