CVE-2008-2100

Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.

Published: 2008-06-05 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-2100 is rated Moderate Risk (44.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.60%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-2100

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.15% 0.60% +0.45%
2 2025-05-05 0.15% 0.15% +0.00%
3 2025-05-02 0.15%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-2100

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.2 2.0 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.9 10.0 [email protected]

Weakness enumeration for CVE-2008-2100

OS Trackers for CVE-2008-2100

vendor priority summary link
gentoo high CVE-2008-2100: 1 GLSA(s) (201209-25), 3 atom(s) (app-emulation/vmware-player, app-emulation/vmware-server, app-emulation/vmware-workstation); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2008-2100
ubuntu medium CVE-2008-2100 medium priority: Ubuntu including 1 source packages (vmware-server), 6 status rows across 6 suites (dapper, feisty, gutsy, hardy, intrepid, upstream): DNE 4, ignored 1, released 1. https://ubuntu.com/security/CVE-2008-2100

Affected software / configurations for CVE-2008-2100

Vendor Product Version Raw CPE
vmware ace >= 1.0, <= 1.0.5 cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*
vmware ace >= 2.0, <= 2.0.3 cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*
vmware esx_server 3.0 cpe:2.3:a:vmware:esx_server:3.0:*:*:*:*:*:*:*
vmware esx_server 3.5 cpe:2.3:a:vmware:esx_server:3.5:*:*:*:*:*:*:*
vmware esxi 3.5 cpe:2.3:a:vmware:esxi:3.5:*:*:*:*:*:*:*
vmware fusion <= 1.1.1 cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
vmware player >= 1.0.0, <= 1.0.6 cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
vmware player >= 2.0, <= 2.0.3 cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
vmware server <= 1.0.5 cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:*
vmware workstation >= 5.5, <= 5.5.6 cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
vmware workstation >= 6.0, <= 6.0.3 cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
vmware esx 2.5.4 cpe:2.3:o:vmware:esx:2.5.4:*:*:*:*:*:*:*
vmware esx 2.5.5 cpe:2.3:o:vmware:esx:2.5.5:*:*:*:*:*:*:*
vmware esx 3.0.0 cpe:2.3:o:vmware:esx:3.0.0:*:*:*:*:*:*:*
vmware esx 3.0.1 cpe:2.3:o:vmware:esx:3.0.1:*:*:*:*:*:*:*
vmware esx 3.0.2 cpe:2.3:o:vmware:esx:3.0.2:*:*:*:*:*:*:*
vmware esx 3.5 cpe:2.3:o:vmware:esx:3.5:*:*:*:*:*:*:*

References for CVE-2008-2100

URL Tags
http://secunia.com/advisories/30556 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201209-25.xml Third Party Advisory
http://securityreason.com/securityalert/3922 Third Party Advisory
http://securitytracker.com/id?1020200 Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/493080/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/29552 Third Party Advisory VDB Entry
http://www.vmware.com/security/advisories/VMSA-2008-0009.html Vendor Advisory
http://www.vupen.com/english/advisories/2008/1744 Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/42872 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5081 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5647 Third Party Advisory
cvelogic Threat Intelligence