imPC@ndo IT

Tracker / CVE-2008-1392

CVE-2008-1392

High 10.0

The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors.

Affected products and versions

vmware ace · … → 2.0
vmware player · … → 2.0.2
vmware vmware_workstation

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References