[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issuesmailing list
http://lists.vmware.com/pipermail/security-announce/2009/000054.html CVE-2008-3761
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
Record summary
CVE-2008-3761 has a selected CVSS score of 4.9; EIP currently links 1 catalogued exploit.
Description
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of ServiceExploitDB exploitby g_Not analyzed1 file
References
1220090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issuesmailing list
http://seclists.org/fulldisclosure/2009/Apr/0036.html 4177Third-party advisory
http://securityreason.com/securityalert/4177 orange-bat.com
http://www.orange-bat.com/adv/2008/adv.08.17.txt 30737vdb entry
http://www.securityfocus.com/bid/30737 34373vdb entry
http://www.securityfocus.com/bid/34373 1020715vdb entry
http://www.securitytracker.com/id?1020715 vmware.comConfirmation
http://www.vmware.com/security/advisories/VMSA-2009-0005.html ADV-2009-0944vdb entry
http://www.vupen.com/english/advisories/2009/0944 vmware-workstation-hcmon-dos(44539)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44539 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-3761 6262exploit
https://www.exploit-db.com/exploits/6262