CVE-2014-1209

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/04/2014
Last modified:
14/04/2014

Description

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:vsphere_client:4.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vsphere_client:4.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vsphere_client:5.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vsphere_client:5.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools