Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

VMware Authorization Service Denial of Service Vulnerability (Windows) -Apr10

Information

Severity

Severity

Medium

Family

Family

Denial of Service

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

13 years ago

Modified

Modified

5 years ago

Summary

The host is installed with VMWare product(s) that are vulnerable to Denial of Service vulnerability.

Insight

Insight

The vulnerability is due to an error in the VMware Authorization Service when processing login requests. This can be exploited to terminate the 'vmware-authd' process via 'USER' or 'PASS' strings containing '\xFF' characters, sent to TCP port 912.

Affected Software

Affected Software

VMware Server 2.x VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459 VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459 VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459

Solution

Solution

Upgrade to player 3.0.1 build 227600 or 2.5.4 build 246459, Upgrade to VMware ACE 2.6.1 build 227600 or 2.5.4 build 246459 Upgrade VMware Workstation 7.0.1 build 227600 and 6.5.4 build 246459 Apply the workaround for VMware Server version 2.x described in the referenced techresource.

Common Vulnerabilities and Exposures (CVE)