Vulnerability Details CVE-2008-1392
The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.0%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2008-1392
-
-
-
cpe:2.3:a:vmware:ace:1.0.1
-
cpe:2.3:a:vmware:ace:1.0.2
-
cpe:2.3:a:vmware:ace:1.0.3
-
cpe:2.3:a:vmware:ace:1.0.3_build_54075
-
cpe:2.3:a:vmware:ace:1.0.4
-
cpe:2.3:a:vmware:ace:1.0.5
-
cpe:2.3:a:vmware:ace:1.0.6
-
cpe:2.3:a:vmware:ace:1.0.7
-
-
cpe:2.3:a:vmware:player:-
-
cpe:2.3:a:vmware:player:1.0
-
cpe:2.3:a:vmware:player:1.0.0
-
cpe:2.3:a:vmware:player:1.0.1
-
cpe:2.3:a:vmware:player:1.0.2
-
cpe:2.3:a:vmware:player:1.0.3
-
cpe:2.3:a:vmware:player:1.0.4
-
cpe:2.3:a:vmware:player:1.0.5
-
cpe:2.3:a:vmware:player:1.0.5_build_56455
-
cpe:2.3:a:vmware:player:1.0.6
-
cpe:2.3:a:vmware:player:1.0.7
-
cpe:2.3:a:vmware:player:1.0.8
-
cpe:2.3:a:vmware:player:1.0.9
-
cpe:2.3:a:vmware:player:2.0
-
cpe:2.3:a:vmware:player:2.0.1
-
cpe:2.3:a:vmware:player:2.0.1_build_55017
-
cpe:2.3:a:vmware:player:2.0.2
-
cpe:2.3:a:vmware:vmware_workstation:6.0.2
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:microsoft:windows:1.0
-
cpe:2.3:o:microsoft:windows:2.0
-
cpe:2.3:o:microsoft:windows:2000
-
cpe:2.3:o:microsoft:windows:3.0
-
cpe:2.3:o:microsoft:windows:3.1
-
cpe:2.3:o:microsoft:windows:3.11
-
cpe:2.3:o:microsoft:windows:server_2008
-
cpe:2.3:o:microsoft:windows:vista