High severity7.8NVD Advisory· Published Nov 16, 2017· Updated May 13, 2026
CVE-2017-16777
CVE-2017-16777
Description
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- m4.rkw.io/blog/cve201716777-local-root-privesc-in-hashicorp-vagrantvmwarefusion-503.htmlnvdExploitIssue TrackingThird Party Advisory
- www.exploit-db.com/exploits/43219/nvd
News mentions
0No linked articles in our index yet.