>> VMware Privilege Escalation and Directory Traversal Vulnerabilities
Title : VMware Privilege Escalation and Directory Traversal Vulnerabilities VUPEN ID : VUPEN/ADV-2008-3052 CVE ID : CVE-2008-4281 - CVE-2008-4915 CWE ID : CWE-22 - CWE-399
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-11-07
Technical Description
Two vulnerabilities have been identified in various VMware products, which could allow local attackers to gain elevated privileges.
The first issue is caused by an error in the CPU hardware emulation when handling the Trap flag, which could allow malicious users on a guest operating systems to gain elevated privileges.
The second vulnerability is caused by an unspecified input validation error which could allow administrators with the "Datastore.FileManagement" privilege to coduct directory traversal attacks and gain elevated privileges.