CVE-2009-3281

Vmware Fusion < 2.0.5 - Access Control

Title source: rule

Description

The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mu-b · clocalosx
https://www.exploit-db.com/exploits/10076

Scores

EPSS 0.0018
EPSS Percentile 39.7%

Details

CWE
CWE-264
Status published
Products (11)
vmware/fusion 1.0
vmware/fusion 1.1
vmware/fusion 1.1.1
vmware/fusion 1.1.2
vmware/fusion 1.1.3
vmware/fusion 2.0
vmware/fusion 2.0.1
vmware/fusion 2.0.2
vmware/fusion 2.0.3
vmware/fusion 2.0.4
... and 1 more
Published Oct 16, 2009
Tracked Since Feb 18, 2026