CVE-2005-4459
🔴 Łataj teraz
Przepełnienie bufora w vmnat.exe i vmnet-natd w VMWare pozwala zdalnie wykonać kod.
CVSS
10.0
EPSS
14.1%
Exploit
poc
Vendor
vmware
Opis źródłowy (NVD)
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
buffer-overflow exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 10.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 14.1% |
| Opublikowano (NVD) | 2005-12-21 20:03:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-07 22:01:29 UTC |
Referencje
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html (cve@mitre.org) [Exploit]
- http://secunia.com/advisories/18162 (cve@mitre.org) [Patch, Vendor Advisory]
- http://secunia.com/advisories/18344 (cve@mitre.org) [Vendor Advisory]
- http://securityreason.com/securityalert/282 (cve@mitre.org) [Third Party Advisory]
- http://securityreason.com/securityalert/289 (cve@mitre.org) [Third Party Advisory]
- http://securitytracker.com/id?1015401 (cve@mitre.org) [Permissions Required]
- http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml (cve@mitre.org) [Third Party Advisory]
- http://www.kb.cert.org/vuls/id/856689 (cve@mitre.org) [US Government Resource]
- http://www.securityfocus.com/archive/1/419997/100/0/threaded (cve@mitre.org) [Broken Link]
- http://www.securityfocus.com/archive/1/420017/100/0/threaded (cve@mitre.org) [Broken Link]
- http://www.securityfocus.com/bid/15998 (cve@mitre.org) [Patch, Broken Link]
- http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000 (cve@mitre.org) [Patch, Broken Link]
- http://www.vupen.com/english/advisories/2005/3013 (cve@mitre.org) [URL Repurposed]