Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2007-1056

Published: 21 February 2007

VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service. NOTE: exploitation is simplified via (1) weak file permissions (Users = Read & Execute) for %PROGRAMFILES%\VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLM\SYSTEM\CurrentControlSet\Services\; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%\VMware\VMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.

Notes

AuthorNote
kees
appears to be Windows-only, or Workstation-only

Priority

Low

Status

Package Release Status
vmware-player
Launchpad, Ubuntu, Debian
dapper Ignored

edgy Ignored

feisty Ignored

gutsy Does not exist

upstream Needs triage

vmware-server
Launchpad, Ubuntu, Debian
dapper Does not exist

edgy Does not exist

feisty Ignored

gutsy Ignored

upstream Needs triage