Exploitation Summary
EIP tracks 3 public exploits for CVE-2017-4915.
PoCs published by Google Security Research, bcoles, Jann Horn, bcoles, including Metasploit module exploits/linux/local/vmware_alsa_config.
AI-analyzed exploit summary This exploit leverages VMWare Workstation's loading of libasound in a setuid context, allowing an unprivileged user to gain root privileges by injecting a malicious shared library via ~/.asoundrc. The library executes a constructor function that escalates privileges when loaded by the vmware-vmx process.
Description
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
Exploits (3)
This exploit leverages VMWare Workstation's loading of libasound in a setuid context, allowing an unprivileged user to gain root privileges by injecting a malicious shared library via ~/.asoundrc. The library executes a constructor function that escalates privileges when loaded by the vmware-vmx process.
This exploit leverages a local privilege escalation vulnerability in VMware Workstation/Player by abusing the sound subsystem to load a malicious shared library, granting root access. It creates a crafted VM configuration and uses the `.asoundrc` file to trigger the payload.
This Metasploit module exploits CVE-2017-4915, a local privilege escalation vulnerability in VMware Workstation Pro and Player on Linux. It leverages an ALSA configuration file to load and execute a malicious shared object as root when a virtual machine with an attached sound card is launched.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H