Vulnerabilities > Hashicorp > Vagrant > 5.0.3

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-16777 Uncontrolled Search Path Element vulnerability in Hashicorp Vagrant 5.0.3
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.
local
low complexity
hashicorp CWE-427
7.2