20120904 VMWare Tools susceptible to binary planting by hijackmailing list
http://archives.neohapsis.com/archives/bugtraq/2012-09/0013.html CVE-2012-1666
ThinPrint - 'tpfc.dll' Insecure Library Loading Arbitrary Code Execution
Record summary
CVE-2012-1666 has a selected CVSS score of 6.9; EIP currently links 1 catalogued exploit.
Description
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBThinPrint - 'tpfc.dll' Insecure Library Loading Arbitrary Code ExecutionExploitDB exploitby Moshe ZioniNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-1666 vmware.comConfirmation
https://www.vmware.com/support/vsphere4/doc/vsp_esxi41_u3_rel_notes.html