CVE-2017-12579

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
19/10/2017
Last modified:
20/04/2025

Description

An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vagrant_vmware_fusion:*:*:*:*:*:*:*:* 4.0.24 (including)