VMware Workstation, Player, and Fusion contain a race condition flaw within the 'vmware-mount' utility when handling temporary files during the mounting process that may allow an attacker to gain access to unauthorized privileges. This may be exploited by a local attacker to gain elevated privileges and create files or directories.
Classification
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, VMWare has released a patch to address this vulnerability.