« Back to list

CVE-2012-2450

Status: ModifiedHigh (9)—

VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (5)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-2450",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-05-04T16:55:01.577",
  "references": [
    {
      "url": "http://osvdb.org/81695",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/49032",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/53369",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1027019",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2012-0009.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75377",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16852",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/81695",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/49032",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/53369",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027019",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2012-0009.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75377",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16852",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS."
    },
    {
      "lang": "es",
      "value": "VMware Workstation v8.x antes de v8.0.3, VMware Player v4.x antes de v4.0.3 VMware Fusion v4.x, antes de v4.1.2, VMware ESXi v3.5 hasta v5.0 y VMware ESX v3.5 hasta v4.1 no registra correctamente los dispositivos SCSI, lo que permite a los usuarios invitados del sistema operativo causar una denegación de servicio (operación de escritura no válida y caída del proceso VMX) o posiblemente ejecutar código arbitrario en el sistema operativo anfitrión mediante el aprovechamiento de privilegios de administrador en el sistema operativo invitado."
    }
  ],
  "lastModified": "2026-06-16T23:41:34.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCE22BB0-F375-4883-BF6C-5A6369694EF3"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD913295-9302-425A-A9E1-B0DF76AD3069"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:8.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51B6CAE2-A396-40C8-8FF0-D9EC64D5C9A0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "535E3D3C-76A5-405A-8F9D-21A86ED31D07"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D09D7FB-78EE-4168-996D-FD3CF2E187BD"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "816F1646-A1C9-4E4A-BCE1-A34D00B51ABE"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:fusion:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60234129-7F7F-49FA-A425-CDAB4D09AB23"
            },
            {
              "criteria": "cpe:2.3:a:vmware:fusion:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FB73EC4-F3CE-428B-BA40-47FB21181543"
            },
            {
              "criteria": "cpe:2.3:a:vmware:fusion:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "927863C2-5A61-4137-83AC-6CF3F2958941"
            },
            {
              "criteria": "cpe:2.3:a:vmware:fusion:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F74559CB-6E52-421F-88F3-739913C26C8E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:fusion:4.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4870DAA2-6670-47EF-BF74-6E39B92E75DB"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAE88D8C-9CC3-46D1-9F26-290BC679F47E"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:3.5:1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58ED8AB4-0FDF-4752-B44E-56F58593CE41"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13771B15-CD71-472A-BE56-718B87D5825D"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.0:1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A4E41C0-31FA-47AA-A9BF-B9A6C1D44801"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.0:2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF016EE7-083A-4D62-A6D4-2807EB47B6DB"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.0:3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F11844A-3C6C-4AA5-87DC-979AFF62867A"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.0:4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC463653-A599-45CF-8EA9-8854D5C59963"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BDE707D-A1F4-4829-843E-F6633BB84D6D"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.1:1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DC5C2BF-6EC6-436F-A925-469E87249C8A"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.1:2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BCE5DA9-BB88-4169-B77C-40B1F98D511A"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2331236-2E9B-4B52-81EE-B52DEB41ACE5"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vmware:esx:3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFF29100-E124-4416-95CF-18B4246D43F2"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:3.5:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37A5D726-3D38-44D5-B509-1B8B003903A0"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:3.5:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4DA3B20-A743-4F37-A095-65161FFBEB73"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:3.5:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF7C3C65-BE63-407E-9CFD-E571025C3E79"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC337BB7-9A45-4406-A783-851F279130EE"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B6BA46F-4E8C-4B2A-AE92-81B9F1B4D56C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}