VMSA-2016-0001 : VMware ESXi, Workstation, Player, and Fusion updates address important guest privilege escalation vulnerability

Medium Nessus Plugin ID 87889


The remote VMware ESXi host is missing a security-related patch.


Important Windows-based guest privilege escalation in VMware Tools

A kernel memory corruption vulnerability is present in the VMware Tools 'Shared Folders' (HGFS) feature running on Microsoft Windows. Successful exploitation of this issue could lead to an escalation of privilege in the guest operating system.

VMware would like to thank Dmitry Janushkevich from the Secunia Research Team for reporting this issue to us.

Note: This vulnerability does not allow for privilege escalation from the guest operating system to the host. Host memory can not be manipulated from the guest operating system by exploiting this flaw.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-6933 to this issue.

Workarounds Removing the 'Shared Folders' (HGFS) feature from previously installed VMware Tools will remove the possibility of exploitation.


Apply the missing patch.

See Also


Plugin Details

Severity: Medium

ID: 87889

File Name: vmware_VMSA-2016-0001.nasl

Version: $Revision: 1.11 $

Type: local

Published: 2016/01/13

Modified: 2016/11/30

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Vulnerability Information

CPE: cpe:/o:vmware:esxi:5.0, cpe:/o:vmware:esxi:5.1, cpe:/o:vmware:esxi:5.5, cpe:/o:vmware:esxi:6.0

Required KB Items: Host/local_checks_enabled, Host/VMware/release, Host/VMware/version

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2016/01/07

Reference Information

CVE: CVE-2015-6933

OSVDB: 132670

VMSA: 2016-0001

IAVB: 2016-B-0013, 2016-B-0014, 2016-B-0015, 2016-B-0016