Vulnerability Details CVE-2008-1392
The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.027
EPSS Ranking 84.2%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2008-1392
-
-
-
cpe:2.3:a:vmware:ace:1.0.1
-
cpe:2.3:a:vmware:ace:1.0.2
-
cpe:2.3:a:vmware:ace:1.0.3
-
cpe:2.3:a:vmware:ace:1.0.3_build_54075
-
cpe:2.3:a:vmware:ace:1.0.4
-
cpe:2.3:a:vmware:ace:1.0.5
-
cpe:2.3:a:vmware:ace:1.0.6
-
cpe:2.3:a:vmware:ace:1.0.7
-
-
cpe:2.3:a:vmware:player:-
-
cpe:2.3:a:vmware:player:1.0
-
cpe:2.3:a:vmware:player:1.0.0
-
cpe:2.3:a:vmware:player:1.0.1
-
cpe:2.3:a:vmware:player:1.0.2
-
cpe:2.3:a:vmware:player:1.0.3
-
cpe:2.3:a:vmware:player:1.0.4
-
cpe:2.3:a:vmware:player:1.0.5
-
cpe:2.3:a:vmware:player:1.0.5_build_56455
-
cpe:2.3:a:vmware:player:1.0.6
-
cpe:2.3:a:vmware:player:1.0.7
-
cpe:2.3:a:vmware:player:1.0.8
-
cpe:2.3:a:vmware:player:1.0.9
-
cpe:2.3:a:vmware:player:2.0
-
cpe:2.3:a:vmware:player:2.0.1
-
cpe:2.3:a:vmware:player:2.0.1_build_55017
-
cpe:2.3:a:vmware:player:2.0.2
-
cpe:2.3:a:vmware:vmware_workstation:6.0.2
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:microsoft:windows:1.0
-
cpe:2.3:o:microsoft:windows:2.0
-
cpe:2.3:o:microsoft:windows:2000
-
cpe:2.3:o:microsoft:windows:3.0
-
cpe:2.3:o:microsoft:windows:3.1
-
cpe:2.3:o:microsoft:windows:3.11
-
cpe:2.3:o:microsoft:windows:server_2008
-
cpe:2.3:o:microsoft:windows:vista