Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder.
2007-09-21T19:17:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | ace | ≤ 1.0.3 | Yes |
Application | vmware | player | ≤ 1.0.5 | Yes |
Application | vmware | player | ≤ 2.0.1 | Yes |
Application | vmware | server | ≤ 1.0.4 | Yes |
Application | vmware | workstation | ≤ 5.5.5 | Yes |
Application | vmware | workstation | ≤ 6.0.1 | Yes |
Operating System | canonical | ubuntu_linux | 6.06 | Yes |
Operating System | canonical | ubuntu_linux | 6.10 | Yes |
Operating System | canonical | ubuntu_linux | 7.04 | Yes |