« Volver al listado

CVE-2013-1662

Estado: ModificadaMedia (6.9)—

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1662",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-08-24T01:55:04.017",
  "references": [
    {
      "url": "http://blog.cmpxchg8b.com/2013/08/security-debianisms.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2013-0010.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.cmpxchg8b.com/2013/08/security-debianisms.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2013-0010.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function."
    },
    {
      "lang": "es",
      "value": "vmware-mount en VMware Workstation v8.x y v9.x y VMware Player v4.x y v5.x, en sistemas basados en Debian GNU/Linux, permite a los usuarios del sistema operativo de host para obtener privilegios del sistema operativo de host manipulando la ruta del directorio del  ejecutable lsb_release, relacionado con el uso de la librería de funciones popen."
    }
  ],
  "lastModified": "2026-06-16T23:51:51.637",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCE22BB0-F375-4883-BF6C-5A6369694EF3"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.0.18997:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01483038-BC89-44BA-B07B-362FC5D7E8C1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD913295-9302-425A-A9E1-B0DF76AD3069"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.1.27038:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B671AC17-7064-4541-ADB3-FCD72109C766"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51B6CAE2-A396-40C8-8FF0-D9EC64D5C9A0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21644868-F1B0-4A8E-BE73-4F42BEB8E834"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4944D9B1-A48B-4F32-951E-BEC3FEAC45FE"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E57BCAA-86E0-4AE1-B30E-1F928CE9E289"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29CBDF44-B9F6-402D-A34C-7B5B16367F8F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B439F706-27F8-4238-9396-B460EB78B6DC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:9.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B87CF2A3-422B-4B5C-9E90-382FF6373F38"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:9.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BF4A5B6-C3E5-47B4-BC9E-14F544E3393E"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "535E3D3C-76A5-405A-8F9D-21A86ED31D07"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.0.18997:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81AFBBE6-0B3B-44DB-BBEB-08C8B2C39038"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D09D7FB-78EE-4168-996D-FD3CF2E187BD"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "816F1646-A1C9-4E4A-BCE1-A34D00B51ABE"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D5FD2D7-9928-437B-8988-4FC955DE4F84"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2932689-76D4-4907-9CF9-AD8F6B801579"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7EE4D64-35A5-46B5-907B-C4ADA14E1288"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4504C4BD-ED32-445C-9957-2BC3ABB29EDC"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:player:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "364FBB12-E292-47BB-8D26-CED34232A135"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEBF8C7B-7034-47B4-B84A-6987EB7B4DC5"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:5.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "277B926D-C575-4526-9F0C-A1D6EAF2AA2D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://www.vmware.com/security/advisories/VMSA-2013-0010.html\n\n\"The issue is present when Workstation or Player are installed on a Debian-based version of Linux.\"",
  "sourceIdentifier": "cve@mitre.org"
}