vmware.comConfirmation
http://www.vmware.com/security/advisories/VMSA-2013-0002.html CVE-2013-1406
VMware Virtual Machine Communication Interface (VMCI) - 'vmci.sys'
Record summary
CVE-2013-1406 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Windows, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 does not properly restrict memory allocation by control code, which allows local users to gain privileges via unspecified vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVMware Virtual Machine Communication Interface (VMCI) - 'vmci.sys'ExploitDB exploitby Artem ShishkinNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-1406 oval:org.mitre.oval:def:17164vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17164