Untrusted search path in VMware Workstation - CVE-2017-4915
Published: May 22, 2017 / Updated: June 17, 2021
Vulnerability identifier: #VU6616
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-4915
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local attacker to gain root privileges on a Linux host machine.
The weakness exists due to untrusted search path. A local attacker who is able to change configuration can load library via ALSA sound driver configuration files, gain elevated privileges and execute arbitrary code on the system.
Successful exploitation of the vulnerability may result in full system compromise.
The weakness exists due to untrusted search path. A local attacker who is able to change configuration can load library via ALSA sound driver configuration files, gain elevated privileges and execute arbitrary code on the system.
Successful exploitation of the vulnerability may result in full system compromise.
Affected software
VMware Workstation
How to mitigate CVE-2017-4915
Update to version 12.5.6.
Links to Public Exploits and PoC-codes
- Exploit #6059 - VMware Workstation/Player < 12.5.5 - Local Privilege Escalation (June 17, 2021)
- Exploit #1202 - VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Config Host Root Privilege Escalation (March 18, 2020)
- Exploit #1809 - VMware Workstation ALSA Config File Local Privilege Escalation (March 18, 2020)