CVE-2007-1056 (CNNVD-200702-393)
中文标题:
VMware Workstation 权限管理和访问控制漏洞
英文标题:
VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged ac...
漏洞描述
中文描述:
VMware Workstation 5.5.3 build 34685没有向每位用户提供ing队某些特权操作的限制,这会允许本地用户执行限制操作,例如更改系统时间,访问硬件组件并中止"Vmware工具服务"的服务。 注意:对该漏洞得利用可以通过(1)对%PROGRAMFILES%\VMware的弱文件许可(Users = Read & Execute); 和对(2)vmmouse,(3)vmscsi,(4)VMTools,(5)vmx_svga,以及(6)HKLM\SYSTEM\CurrentControlSet\Services\中的vmxnet的弱注册索引许可(通过Users访问)而变得简单; 这会允许本地用户通过运行在%PROGRAMFILES%\VMware\VMware工具下的某些文件了,例如(a) VMControlPanel.cpl和(b)vmwareservice.exe,以执行客户操作系统之外的不同的特权操作。
英文描述:
VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service. NOTE: exploitation is simplified via (1) weak file permissions (Users = Read & Execute) for %PROGRAMFILES%\VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLM\SYSTEM\CurrentControlSet\Services\; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%\VMware\VMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| vmware | workstation | 5.5.3_build_34685 | - | - |
cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:L/AC:L/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-1056 |
2025-11-11 15:17:50 | 2025-11-11 07:32:41 |
| NVD | nvd_CVE-2007-1056 |
2025-11-11 14:52:09 | 2025-11-11 07:41:27 |
| CNNVD | cnnvd_CNNVD-200702-393 |
2025-11-11 15:08:55 | 2025-11-11 07:49:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200702-393
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.2
- cvss_vector: NOT_EXTRACTED -> AV:L/AC:L/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']