CVE-2007-5671
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.
Published:Jun 5, 2008
Last Modified:Apr 23, 2026
EPS:Jun 5, 2008
EPSS Score:0.00116
CVSS Score:4.4
Affected Products
Vendor
Product
Action
Vendor
Vmware
Product
Ace
Vmware
Ace
Vendor
Vmware
Product
Esx
Vmware
Esx
Vendor
Vmware
Product
Esx Server
Vmware
Esx Server
Vendor
Vmware
Product
Player
Vmware
Player
Vendor
Vmware
Product
Server
Vmware
Server
Vendor
Vmware
Product
Vmware Player
Vmware
Vmware Player
Vendor
Vmware
Product
Vmware Server
Vmware
Vmware Server
Vendor
Vmware
Product
Vmware Workstation
Vmware
Vmware Workstation
Vendor
Vmware
Product
Workstation
Vmware
Workstation
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
