CVE-2017-16001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
06/11/2017
Last modified:
20/04/2025

Description

In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vagrant:5.0.1:*:*:*:*:vmware_fusion:*:*