VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1037103 | vdb entry |
http://www.vmware.com/security/advisories/VMSA-2016-0017.html | vendor advisory |
http://www.securityfocus.com/bid/93888 | vdb entry third party advisory |