CVE-2009-1244

VMware <1.0.9 build 156507 - RCE

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.

Exploits (1)

nomisec WORKING POC 1 stars
by piotrbania · poc
https://github.com/piotrbania/vmware_exploit_pack_CVE-2009-1244

References (10)

Core 10
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201209-25.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49834
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34471
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022031
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53634
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6065
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0944
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2009/000055.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502615/100/0/threaded

Scores

EPSS 0.0063
EPSS Percentile 70.4%

Details

Status published
Products (50)
vmware/ace 1.0
vmware/ace 1.0.0
vmware/ace 1.0.1
vmware/ace 1.0.2
vmware/ace 1.0.3
vmware/ace 1.0.4
vmware/ace 1.0.5
vmware/ace 1.0.6
vmware/ace 1.0.7
vmware/ace 2.0
... and 40 more
Published Apr 13, 2009
Tracked Since Feb 18, 2026