VMware Support Insecure File Access Vulnerability (CVE-2014-4200)
Release date:
Updated on:
Affected Systems:
VMWare VMware Support Tool 0.88
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69410
CVE (CAN) ID: CVE-2014-4200
VMware Support is a tool for collecting diagnostic information from a virtualized client system.
VMware Support 0.88 and other versions have incorrect permissions on the tmp directory. Attackers can exploit this vulnerability to obtain sensitive information.
<* Source: dolevfarhi
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.vmware.com/security/
This article permanently updates the link address: