CVE-2009-3732
VMware ACE 2.5.0-2.5.3 - Remote Code Execution via Format String Vulnerability
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3732. PoCs published by Alexey Sintsov.
AI-analyzed exploit summary The advisory describes a format string vulnerability in VMware Remote Console Plug-in (CVE-2009-3732), which can be exploited via malformed shortcut parameters or a crafted HTML page using ActiveX. Exploitation may lead to arbitrary code execution on the system where VMrc is installed.
Description
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
Exploits (1)
The advisory describes a format string vulnerability in VMware Remote Console Plug-in (CVE-2009-3732), which can be exploited via malformed shortcut parameters or a crafted HTML page using ActiveX. Exploitation may lead to arbitrary code execution on the system where VMrc is installed.