VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.vmware.com/security/advisories/VMSA-2017-0021.html | patch vendor advisory |
http://www.securitytracker.com/id/1040026 | vdb entry third party advisory |