VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93886 | vdb entry third party advisory |
http://www.vmware.com/security/advisories/VMSA-2016-0017.html | vendor advisory |
http://www.securitytracker.com/id/1037102 | vdb entry |