Show plain JSON{"id": "CVE-2008-0923", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.9, "accessVector": "LOCAL", "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "MEDIUM", "obtainAllPrivilege": true, "exploitabilityScore": 3.4, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2008-02-26T00:44:00.000", "references": [{"url": "http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004034", "source": "cve@mitre.org"}, {"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060457.html", "source": "cve@mitre.org"}, {"url": "http://lists.vmware.com/pipermail/security-announce/2008/000008.html", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/29117", "source": "cve@mitre.org"}, {"url": "http://securityreason.com/securityalert/3700", "source": "cve@mitre.org"}, {"url": "http://www.coresecurity.com/?action=item&id=2129", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/488725/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/489739/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/27944", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/28276", "source": "cve@mitre.org"}, {"url": "http://www.securitytracker.com/id?1019493", "source": "cve@mitre.org"}, {"url": "http://www.vmware.com/security/advisories/VMSA-2008-0005.html", "source": "cve@mitre.org"}, {"url": "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html", "source": "cve@mitre.org"}, {"url": "http://www.vmware.com/support/player/doc/releasenotes_player.html", "source": "cve@mitre.org"}, {"url": "http://www.vmware.com/support/player2/doc/releasenotes_player2.html", "source": "cve@mitre.org"}, {"url": "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html", "source": "cve@mitre.org"}, {"url": "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html", "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2008/0679", "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2008/0905/references", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40837", "source": "cve@mitre.org"}, {"url": "http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004034", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060457.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://lists.vmware.com/pipermail/security-announce/2008/000008.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/29117", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securityreason.com/securityalert/3700", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.coresecurity.com/?action=item&id=2129", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/488725/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/489739/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/27944", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/28276", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id?1019493", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vmware.com/security/advisories/VMSA-2008-0005.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vmware.com/support/player/doc/releasenotes_player.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vmware.com/support/player2/doc/releasenotes_player2.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2008/0679", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2008/0905/references", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40837", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-22"}]}], "descriptions": [{"lang": "en", "value": "Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a \"%c0%2e%c0%2e\" string."}, {"lang": "es", "value": "Vulnerabilidad de salto de directorio en la caracter\u00edstica de Archivos Compartidos de VMWare ACE 1.0.2 y 2.0.2, Player 1.0.4 y 2.0.2, y Workstation 5.5.4 y 6.0.2 permite a usuarios de SO invitados leer y escribir archivos de su elecci\u00f3n en el SO anfitri\u00f3n a trav\u00e9s de una cadena multibyte que produce una cadena de caracteres ancha que contiene secuencias de .. (punto punto), lo que evita el mecanismo de protecci\u00f3n, como se demostr\u00f3 usando una cadena \"%c0%2e%c0%2e\"."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:vmware:ace:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6F20A8E8-E07D-41B2-899F-2ABA9DD1C2C6"}, {"criteria": "cpe:2.3:a:vmware:ace:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D346E48-887C-4D02-BFD3-D323B7F3871C"}, {"criteria": "cpe:2.3:a:vmware:ace:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8E1A5AA-BD9F-4263-B7C6-E744323C4D74"}, {"criteria": "cpe:2.3:a:vmware:ace:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D22E40D-C362-49FD-924C-262A64555934"}, {"criteria": "cpe:2.3:a:vmware:ace:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A48CEB4-5864-4A0F-B14C-CFE4699C3311"}, {"criteria": "cpe:2.3:a:vmware:player:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6F2F6AF4-5987-43BC-9183-5DF7D6DE1EFE"}, {"criteria": "cpe:2.3:a:vmware:vmware_player:1.0.1_build_19317:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7764D48A-2D43-413F-9214-AE754DDCF68F"}, {"criteria": "cpe:2.3:a:vmware:vmware_player:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65DD6966-72EA-4C4D-BC90-B0D534834BA8"}, {"criteria": "cpe:2.3:a:vmware:vmware_player:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBFC9B7A-8A40-467B-9102-EE5259EC4D14"}, {"criteria": "cpe:2.3:a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B7632A4-D120-434D-B35A-303640DB37AB"}, {"criteria": "cpe:2.3:a:vmware:vmware_workstation:6.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DFFE01E-BD0A-432E-B47C-D68DAADDD075"}, {"criteria": "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD0FE7C5-2C46-4B59-9242-A03B986C07DF"}, {"criteria": "cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51C6D608-64DE-4CC4-9869-3342E8FD707F"}, {"criteria": "cpe:2.3:a:vmware:workstation:5.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16A1141D-9718-4A22-8FF2-AEAD28E07291"}, {"criteria": "cpe:2.3:a:vmware:workstation:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89329F80-7134-4AB2-BDA3-E1B887F633B0"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}