VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.
2014-04-11T19:55:04.493
2025-04-12T10:46:40.837
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | vmware | vsphere_client | 4.0 | Yes |
| Application | vmware | vsphere_client | 4.1 | Yes |
| Application | vmware | vsphere_client | 5.0 | Yes |
| Application | vmware | vsphere_client | 5.1 | Yes |