CVE-2015-5191
Severity CVSS v4.0:
Pending analysis
Type:
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
28/07/2017
Last modified:
20/04/2025
Description
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
3.70
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* | 10.0.8 (including) | |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page