CVE-2009-3281
highCVSS v3 Base Score
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Score
0.2%
Exploitation probability in 30 days
Top 60% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Published: October 16, 2009 (6054 days ago)
Last Modified: April 23, 2026
Vendor: VMware
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.
CWE
CWE-264Affected Products
vmware fusion