vendor:
Vmware
by:
callAX, GoodFellas Security Research Team
7.5
CVSS
HIGH
Arbitrary Data Write
22
CWE
Product Name: Vmware
Affected Version From: 5.5.3.42958
Affected Version To: 5.5.3.42958
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP1/SP2 french/english with IE 6.0 / 7.0
2007
IntraProcessLogging.dll 5.5.3.42958 VmWare Inc Arbitrary Data Write Exploit
The SetLogFileName method in IntraProcessLogging.dll does not check if it's being called from the application or by malicious users. This allows a remote attacker to craft a HTML page and overwrite arbitrary files on the system.
Mitigation:
Activate the Kill bit zero in clsid:AF13B07E-28A1-4CAC-9C9A-EC582E354A24 and unregister IntraProcessLogging.dll using regsvr32.