CVE-2010-4297
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS users to gain privileges on the guest OS via unspecified vectors, related to a "command injection" issue.
Published:Dec 6, 2010
Last Modified:Apr 11, 2025
EPS:Dec 6, 2010
EPSS Score:0.02398
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Vmware
Product
Esx
Vmware
Esx
Vendor
Vmware
Product
Esxi
Vmware
Esxi
Vendor
Vmware
Product
Fusion
Vmware
Fusion
Vendor
Vmware
Product
Player
Vmware
Player
Vendor
Vmware
Product
Server
Vmware
Server
Vendor
Vmware
Product
Workstation
Vmware
Workstation
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
