VMware vCenter Server Appliance Elevated Privileges Vulnerability
Last Update Date:
18 Jun 2014 12:25
Release Date:
18 Jun 2014
3720
Views
RISK: High Risk
TYPE: Servers - Other Servers
A vulnerability was identified in VMware vCenter Server Appliance. A remote authenticated user can execute commands on the target system with elevated privileges.
A remote authenticated user can send specially crafted data to escape a chroot jail via the Ruby vSphere Console (RVC) and execute commands with root privileges.
Impact
- Elevation of Privilege
- Remote Code Execution
System / Technologies affected
- VMware vCenter Server Appliance
Solutions
NOTE: There is no patch available for this vulnerability.
- Workaround:
The vendor's advisory is available at http://www.zerodayinitiative.com/advisories/ZDI-14-159/
Vulnerability Identifier
Source
Related Link
Share with