header-logo
Suggest Exploit
vendor:
Workstation Player
by:
bcoles
7.8
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Workstation Player
Affected Version From: 12.5.5
Affected Version To: 12.5.5
Patch Exists: YES
Related CWE: CVE-2017-4915
CPE: a:vmware:workstation_player:12.5.5
Other Scripts: N/A
Platforms Tested: Linux
2017

VMware Workstation Local Privilege Escalation exploit (CVE-2017-4915)

This exploit is for VMware Workstation Player and Pro versions 12.5.5 and below. It creates a directory, writes a C program to it, compiles it, removes the C program, and writes an .asoundrc file. It then executes the vmplayer binary, which loads the shared object file and runs the code, granting the user root privileges.

Mitigation:

Upgrade to the latest version of VMware Workstation Player and Pro.
Source

Exploit-DB raw data: