CVE-2017-15884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
31/10/2017
Last modified:
20/04/2025

Description

In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vagrant_vmware_fusion:5.0.0:*:*:*:*:*:*:*