CVE-2017-7642
02.08.2017, 19:29
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.Enginsight
| Vendor | Product | Version |
|---|---|---|
| hashicorp | vagrant_vmware_fusion | 𝑥 ≤ 4.0.20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References