CVE-2008-4279 is a privilege escalation vulnerability affecting VMware Workstation, Player, Server, and ESX, where an authenticated 64-bit guest OS user can gain elevated guest OS privileges. This is achieved by triggering an exception in the CPU hardware emulation, causing an indirect jump to a non-canonical address. With a CVSS score of 6.8, it represents a high-severity local attack requiring authentication, leading to complete compromise of confidentiality, integrity, and availability within the guest OS. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, < 1.0.8CPE matchmatch criteria | cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:* | ||
>= 1.0, < 1.0.8CPE matchmatch criteria | cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.5.8CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.