vendor:
Vmware
by:
callAX, GoodFellas Security Research Team
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Vmware
Affected Version From: 2.2.5.42958
Affected Version To: 2.2.5.42958
Patch Exists: NO
Related CWE:
CPE: vmware:vielib:2.2.5.42958
Platforms Tested: Windows XP SP1/SP2 french/english with IE 6.0 / 7.0
2007
vielib.dll 2.2.5.42958 VmWare Inc version 6.0.0 Remode Code Execution Exploit
The StartProcess method in vielib.dll in Vmware Version 6.0.0 does not check if it's being called from the application or by malicious users. This allows remote attackers to execute arbitrary code in a remote system with the actual user privileges.
Mitigation:
Activate the Kill bit zero in clsid:7B9C5422-39AA-4C21-BEEF-645E42EB4529, Unregister vielib.dll using regsvr32