Vulnerability Details CVE-2008-1392
The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 75.1%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2008-1392
-
-
-
cpe:2.3:a:vmware:ace:1.0.1
-
cpe:2.3:a:vmware:ace:1.0.2
-
cpe:2.3:a:vmware:ace:1.0.3
-
cpe:2.3:a:vmware:ace:1.0.3_build_54075
-
cpe:2.3:a:vmware:ace:1.0.4
-
cpe:2.3:a:vmware:ace:1.0.5
-
cpe:2.3:a:vmware:ace:1.0.6
-
cpe:2.3:a:vmware:ace:1.0.7
-
-
cpe:2.3:a:vmware:player:-
-
cpe:2.3:a:vmware:player:1.0
-
cpe:2.3:a:vmware:player:1.0.0
-
cpe:2.3:a:vmware:player:1.0.1
-
cpe:2.3:a:vmware:player:1.0.2
-
cpe:2.3:a:vmware:player:1.0.3
-
cpe:2.3:a:vmware:player:1.0.4
-
cpe:2.3:a:vmware:player:1.0.5
-
cpe:2.3:a:vmware:player:1.0.5_build_56455
-
cpe:2.3:a:vmware:player:1.0.6
-
cpe:2.3:a:vmware:player:1.0.7
-
cpe:2.3:a:vmware:player:1.0.8
-
cpe:2.3:a:vmware:player:1.0.9
-
cpe:2.3:a:vmware:player:2.0
-
cpe:2.3:a:vmware:player:2.0.1
-
cpe:2.3:a:vmware:player:2.0.1_build_55017
-
cpe:2.3:a:vmware:player:2.0.2
-
cpe:2.3:a:vmware:vmware_workstation:6.0.2
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:microsoft:windows:1.0
-
cpe:2.3:o:microsoft:windows:2.0
-
cpe:2.3:o:microsoft:windows:2000
-
cpe:2.3:o:microsoft:windows:3.0
-
cpe:2.3:o:microsoft:windows:3.1
-
cpe:2.3:o:microsoft:windows:3.11
-
cpe:2.3:o:microsoft:windows:server_2008
-
cpe:2.3:o:microsoft:windows:vista