CVE-2014-2384

vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation and system crash) via a crafted buffer in an IOCTL call. NOTE: the researcher reports "Vendor rated issue as non-exploitable."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:player:6.0.1_build_1379776:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:10.0.1_build_1379776:*:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2014/Apr/163 - () http://seclists.org/fulldisclosure/2014/Apr/163 -
References () https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2384/ - () https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2384/ -

Information

Published : 2014-04-15 23:13

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2384

Mitre link : CVE-2014-2384

CVE.ORG link : CVE-2014-2384


JSON object : View

Products Affected

vmware

  • player
  • workstation
CWE
CWE-399

Resource Management Errors