VMware vCenter Server Appliance Local Elevation of Privilege (CVE-2017-4943)
VMware vCenter Server Appliance Local Elevation of Privilege (CVE-2017-4943)
Release date:
Updated on:
Affected Systems:
VMWare vCenter Server Appliance (vCSA) 6.5 <6.5 U1d
Description:
Bugtraq id: 102242
CVE (CAN) ID: CVE-2017-4943
VMware vCenter Server can quickly deploy virtual machines and monitor the performance of physical servers and virtual machines.
VMware vCenter Server Appliance (vCSA) (6.5 <6.5 U1d) has a local permission Escalation Vulnerability. Attackers can use the showlog plug-in to gain permission escalation.
<* Source: Lukasz Plonka
*>
Suggestion:
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com
Https://www.vmware.com/security/advisories/VMSA-2017-0021.html