Security bypass in VMware Fusion - CVE-2016-5329
Published: October 26, 2016 / Updated: October 31, 2016
Vulnerability identifier: #VU1101
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:A/U:Clear
CVE-ID: CVE-2016-5329
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: VMware, Inc
Affected software:
VMware Fusion
VMware Fusion
Detailed vulnerability description
The vulnerability allows a local user to bypass security restrictions on the target system.
The weakness is due to access control flaw. By obtaining kernel memory address information, a local attacker can bypass address space layout randomization (ASLR) security protections.
Successful exploitation of the vulnerability results in access to the vulnerable system.
The weakness is due to access control flaw. By obtaining kernel memory address information, a local attacker can bypass address space layout randomization (ASLR) security protections.
Successful exploitation of the vulnerability results in access to the vulnerable system.
How to mitigate CVE-2016-5329
Update to version 8.5.