CVE Feed

    Dashboard / CVE / CVE-2010-4297

    CVE-2010-4297

    The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS users to gain privileges on the guest OS via unspecified vectors, related to a "command injection" issue.

    Published:Dec 6, 2010
    Last Modified:Apr 11, 2025
    EPS:Dec 6, 2010
    EPSS Score:0.02398
    CVSS Score:7.2

    Affected Products

    Vendor
    Vmware
    Product
    Esx
    Vendor
    Vmware
    Product
    Esxi
    Vendor
    Vmware
    Product
    Fusion
    Vendor
    Vmware
    Product
    Player
    Vendor
    Vmware
    Product
    Server
    Vendor
    Vmware
    Product
    Workstation

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High