Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder.
| Software | From | Fixed in |
|---|---|---|
| vmware / workstation | 5 | 5.5.5.x |
| vmware / workstation | 6.0 | 6.0.1.x |
| vmware / player | 1.0.0 | 1.0.5.x |
| vmware / player | 2.0 | 2.0.1.x |
| vmware / ace | 1.0 | 1.0.3.x |
| vmware / server | 1.0 | 1.0.4.x |
| canonical / ubuntu_linux | 6.06 | 6.06.x |
| canonical / ubuntu_linux | 7.04 | 7.04.x |
| canonical / ubuntu_linux | 6.10 | 6.10.x |