ZeroHour

CVE-2017-7642

PoC ×2
CVSS 3.0
7.8 high
EPSS
1%p67
Published
()
Modified
Description

The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.

Vendors
hashicorp
Products
vagrant vmware fusion
Weakness
CWE-426
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.