CVE-2014-1209
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.vmware.com/security/advisories/VMSA-2014-0003.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| vmware | vsphere_client | 4.0 | |
| vmware | vsphere_client | 4.1 | |
| vmware | vsphere_client | 5.0 | |
| vmware | vsphere_client | 5.1 | |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.