Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-5511. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a process impersonation vulnerability in VMware Workstation/Player on Windows, allowing a non-admin user to hijack the VMX process creation by replacing the executable path via drive letter manipulation. The fake VMX process can then use privileged commands like 'opensecurable' to escalate privileges to SYSTEM.
Description
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Exploits (1)
This exploit leverages a process impersonation vulnerability in VMware Workstation/Player on Windows, allowing a non-admin user to hijack the VMX process creation by replacing the executable path via drive letter manipulation. The fake VMX process can then use privileged commands like 'opensecurable' to escalate privileges to SYSTEM.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H