CVE-2008-4915

The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.

Published: 2008-11-10 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-4915 is rated Low Risk (39.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.41%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-4915

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.07% 0.41% +0.34%
2 2025-05-05 0.05% 0.07% +0.03%
3 2025-03-30 0.05%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-4915

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.9 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.4 10.0 [email protected]

Weakness enumeration for CVE-2008-4915

OS Trackers for CVE-2008-4915

vendor priority summary link
gentoo high CVE-2008-4915: 1 GLSA(s) (201209-25), 3 atom(s) (app-emulation/vmware-player, app-emulation/vmware-server, app-emulation/vmware-workstation); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2008-4915
ubuntu medium CVE-2008-4915 medium priority: Ubuntu including 2 source packages (vmware-player, vmware-server), 14 status rows across 7 suites (dapper, gutsy, hardy, intrepid, jaunty, karmic, upstream): DNE 11, needs-triage 2, ignored 1. https://ubuntu.com/security/CVE-2008-4915

Affected software / configurations for CVE-2008-4915

Vendor Product Version Raw CPE
vmware ace >= 1.0, <= 1.0.7 cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*
vmware ace >= 2.0, <= 2.0.5 cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*
vmware esx >= 2.5.4, <= 3.5 cpe:2.3:a:vmware:esx:*:*:*:*:*:*:*:*
vmware esxi 3.5 cpe:2.3:a:vmware:esxi:3.5:*:*:*:*:*:*:*
vmware player >= 1.0.0, <= 1.0.8 cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
vmware player >= 2.0, <= 2.0.5 cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
vmware server >= 1.0, <= 1.0.7 cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:*
vmware workstation >= 5.5, <= 5.5.8 cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
vmware workstation >= 6.0, <= 6.0.5 cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*

References for CVE-2008-4915

URL Tags
http://lists.vmware.com/pipermail/security-announce/2008/000042.html Vendor Advisory
http://secunia.com/advisories/32612 Third Party Advisory
http://secunia.com/advisories/32624 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201209-25.xml Third Party Advisory
http://www.securityfocus.com/archive/1/498138/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/32168 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1021154 Third Party Advisory VDB Entry
http://www.vmware.com/security/advisories/VMSA-2008-0018.html Vendor Advisory
http://www.vupen.com/english/advisories/2008/3052 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/46415 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6309 Third Party Advisory
cvelogic Threat Intelligence