- Description
- VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
- nvd@nist.gov
- CWE-200
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:fusion:8.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25BBD4C7-C851-4D40-B6DD-92873319CD28"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:8.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20453B9E-D3AD-403F-B1A5-FB3300FBB0C0"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:8.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6759F732-8E65-49F7-B46C-B1E3F856B11D"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:8.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDD345B3-810C-41D1-82CE-0CA0B4B1F5DF"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:8.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D91C182F-A8D2-4ABF-B202-261056EF93D1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]