CVE-2010-4295

Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via vectors involving temporary files.

Published: 2010-12-06 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-4295 is rated Low Risk (32.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2010-4295

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.19% 0.06% -0.13%
2 2024-12-17 0.06% 0.19% +0.12%
3 2023-03-07 0.06%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-4295

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.9 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.4 10.0 [email protected]

Weakness enumeration for CVE-2010-4295

Affected software / configurations for CVE-2010-4295

Vendor Product Version Raw CPE
vmware workstation 7.0 cpe:2.3:a:vmware:workstation:7.0:*:*:*:*:*:*:*
vmware workstation 7.0.1 cpe:2.3:a:vmware:workstation:7.0.1:*:*:*:*:*:*:*
vmware workstation 7.1 cpe:2.3:a:vmware:workstation:7.1:*:*:*:*:*:*:*
vmware workstation 7.1.1 cpe:2.3:a:vmware:workstation:7.1.1:*:*:*:*:*:*:*
vmware workstation 7.1.2 cpe:2.3:a:vmware:workstation:7.1.2:*:*:*:*:*:*:*
vmware player 3.1 cpe:2.3:a:vmware:player:3.1:*:*:*:*:*:*:*
vmware player 3.1.1 cpe:2.3:a:vmware:player:3.1.1:*:*:*:*:*:*:*
vmware player 3.1.2 cpe:2.3:a:vmware:player:3.1.2:*:*:*:*:*:*:*
vmware server 2.0.2 cpe:2.3:a:vmware:server:2.0.2:*:*:*:*:*:*:*
vmware fusion 3.1 cpe:2.3:a:vmware:fusion:3.1:*:*:*:*:*:*:*
vmware fusion 3.1.1 cpe:2.3:a:vmware:fusion:3.1.1:*:*:*:*:*:*:*
vmware fusion 3.1.2 cpe:2.3:a:vmware:fusion:3.1.2:*:*:*:*:*:*:*

References for CVE-2010-4295

URL Tags
http://lists.vmware.com/pipermail/security-announce/2010/000112.html Mailing List Vendor Advisory
http://osvdb.org/69585 Broken Link
http://secunia.com/advisories/42453 Broken Link Vendor Advisory
http://secunia.com/advisories/42482 Broken Link Vendor Advisory
http://www.securityfocus.com/archive/1/514995/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/45167 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1024819 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1024820 Broken Link Third Party Advisory VDB Entry
http://www.vmware.com/security/advisories/VMSA-2010-0018.html Vendor Advisory
http://www.vupen.com/english/advisories/2010/3116 Broken Link Vendor Advisory
cvelogic Threat Intelligence