Vulnerabilities > CVE-2012-4897 - Unspecified vulnerability in VMWare Movie Decoder
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN vmware
nessus
Summary
Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | Windows |
NASL id | VMWARE_MOVIE_DECODER_9_0.NASL |
description | The version of VMware Movie Decoder installed on the remote host is earlier than 9.0 and is, therefore, affected by a DLL loading vulnerability. This issue potentially allows for a local attacker to execute custom code by writing a malicious executable into the same directory as the VMware Movie Installer. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 63113 |
published | 2012-11-30 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/63113 |
title | VMware Movie Decoder < 9.0 Path Subversion Arbitrary DLL Injection Code Execution (VMSA-2012-0014) |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0069.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0069.html
- http://osvdb.org/85957
- http://osvdb.org/85957
- http://www.securityfocus.com/bid/55802
- http://www.securityfocus.com/bid/55802
- http://www.vmware.com/security/advisories/VMSA-2012-0014.html
- http://www.vmware.com/security/advisories/VMSA-2012-0014.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79046