CVE-2009-2267

EXPLOITED

VMware ESX <4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-2267 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Tavis Ormandy & Julien Tinnes.

AI-analyzed exploit summary This is a vulnerability writeup for CVE-2009-2267, detailing affected VMWare products and versions. It does not contain exploit code but provides references to an external exploit archive.

Description

VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Tavis Ormandy & Julien Tinnes · textlocalmultiple
https://www.exploit-db.com/exploits/10207

This is a vulnerability writeup for CVE-2009-2267, detailing affected VMWare products and versions. It does not contain exploit code but provides references to an external exploit archive.

Classification
Writeup 90%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: VMWare Workstation, Server, Player, Fusion, ESXi, ESX, ACE (multiple versions)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201209-25.xml
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3062
Vendor Advisory mailing-list x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2009/000069.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023082
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36841
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8473
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507523/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507539/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023083
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2009-0015.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37172

Scores

EPSS 0.0255
EPSS Percentile 85.9%

Details

VulnCheck KEV 2026-02-09
Status published
Products (33)
vmware/ace 2.5.0
vmware/ace 2.5.1
vmware/ace 2.5.2
vmware/esx 2.5.5
vmware/esx 3.0.3
vmware/esx 3.5
vmware/esx 4.0
vmware/esxi 3.5
vmware/esxi 4.0
vmware/fusion 2.0
... and 23 more
Published Nov 02, 2009
Tracked Since Feb 18, 2026