ZeroHour

CVE-2017-11741

PoC
CVSS 3.0
8.8 high
EPSS
1%p64
Published
()
Modified
Description

HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.

Vendors
hashicorp
Products
vagrant vmware fusion
Weakness
CWE-276
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.