vendor:
Vagrant VMware Fusion
by:
m4rkw
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Vagrant VMware Fusion
Affected Version From: 5.0.0
Affected Version To: 5.0.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: macOS
2020
Vagrant VMware Fusion 5.0.1 Root Privilege Escalation
A local attacker or malware can exploit the installation process of version 5.0.0 of the Vagrant VMware Fusion plugin to escalate privileges to root. The mitigations pushed by Hashicorp for this issue were not sufficient as 5.0.1 is still exploitable with a slightly different approach. The issue is fixed in version 5.0.2.
Mitigation:
Upgrade to version 5.0.2 of the Vagrant VMware Fusion plugin.