peter bassill · operator
$ cve CVE-2008-3892 JSON

CVE-2008-3892 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 24.4% (pctl 98)

Patch early

A public exploit exists.

Description

Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call. NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS24.36% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-09-03
Last modified2026-06-16

Affected (4)

VendorProduct
vmwareace
vmwareplayer
vmwareserver
vmwareworkstation

Public exploits

SourceTitleDate
exploit-dbVMware - COM API ActiveX Remote Buffer Overflow (PoC)2008-09-01

References

→ the Explorer  ·  watch your stack  ·  NVD