CVE-2009-3707

VMware Workstation/Player/ACE/Server DoS via Format String in Auth Daemon

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3707. PoCs published by shinnai.

AI-analyzed exploit summary This exploit targets a format string vulnerability in VMware Authorization Service (vmware-authd.exe) <= 2.5.3, causing a denial-of-service by sending malformed USER and PASS commands with format string specifiers. The PoC crashes the service by leveraging improper input validation.

Description

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · pythondoswindows
https://www.exploit-db.com/exploits/33271

This exploit targets a format string vulnerability in VMware Authorization Service (vmware-authd.exe) <= 2.5.3, causing a denial-of-service by sending malformed USER and PASS commands with format string specifiers. The PoC crashes the service by leveraging improper input validation.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: VMware Authorization Service (vmware-authd.exe) <= 2.5.3
No auth needed
Prerequisites: Network access to the target service on port 912
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Various Sources mailing-list x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2010/000090.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201209-25.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39206
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36630
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1022997
Exploit, URL Repurposed x_refsource_misc
http://www.shinnai.net/xplits/TXT_JtYUv6C6j5b6Bw6iIkF4.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36988
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39215
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html

Scores

EPSS 0.1111
EPSS Percentile 95.4%

Details

CWE
CWE-134
Status published
Products (24)
vmware/ace 2.5.0
vmware/ace 2.5.1
vmware/ace 2.5.2
vmware/ace 2.5.3
vmware/ace 2.5.4
vmware/ace 2.6
vmware/ace 2.6.1
vmware/player 2.5
vmware/player 2.5.1
vmware/player 2.5.2
... and 14 more
Published Oct 16, 2009
Tracked Since Feb 18, 2026