VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.
| Software | From | Fixed in |
|---|---|---|
| vmware / vcenter_server | 6.5-f | 6.5-f.x |
| vmware / vcenter_server | 6.5-e | 6.5-e.x |
| vmware / vcenter_server | 6.5-d | 6.5-d.x |
| vmware / vcenter_server | 6.5-c | 6.5-c.x |
| vmware / vcenter_server | 6.5-b | 6.5-b.x |
| vmware / vcenter_server | 6.5-a | 6.5-a.x |
| vmware / vcenter_server | 6.5-update1 | 6.5-update1.x |
| vmware / vcenter_server | 6.5-update1c | 6.5-update1c.x |
| vmware / vcenter_server | 6.5-update1b | 6.5-update1b.x |