« Volver al listado

CVE-2014-1209

Estado: ModificadaAlta (9.3)—

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-1209",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-11T19:55:04.493",
  "references": [
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2014-0003.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2014-0003.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "VMware vSphere Client 4.0, 4.1, 5.0 anterior a Update 3 y 5.1 anterior a Update 2 no valida debidamente actualizaciones a archivos de clientes, lo que permite a atacantes remotos provocar la descarga y ejecución de un programa arbitrario a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:04:32.063",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_client:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CA62BF5-5C65-4F95-99EB-BD035C54132E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_client:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A071FED-5E7E-4A46-8287-21BEE3F9A9A8"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_client:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD888822-0F81-416E-99E9-98566A2CE00F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_client:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE0B5F76-A1B9-42CB-AB0A-FDF47894D0D3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}