Vulnerability record · CVE-2009-3733 · published 2 November 2009
CVE-2009-3733: VMware Server, ESX and ESXi directory traversal allows arbitrary file read
Vmware · Esx
A directory traversal flaw (CWE-22) exists in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5. The description does not specify the vulnerable component or the exact traversal vectors, so the precise request path is unknown from this record. It matters because unauthenticated remote attackers can read files outside the intended directory on virtualization hosts.
Description
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file read on virtualization hosts is serious, and EPSS is very high, though the CVSS 2.0 base score is only 5.0 and there is no confirmed in-the-wild exploitation.
What it is
A directory traversal flaw (CWE-22) exists in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5. The description does not specify the vulnerable component or the exact traversal vectors, so the precise request path is unknown from this record. It matters because unauthenticated remote attackers can read files outside the intended directory on virtualization hosts.
Impact
An attacker gains read access to arbitrary files on the affected host, which can expose configuration data, credentials or other sensitive content. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with no authentication (Au:N) and no user interaction, per the CVSS 2.0 vector. The description does not identify which service or interface carries the traversal request.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.83378 probability, 99.664th percentile). References are vendor advisories, patch notices and third-party VDB entries; none are tagged as exploit code.
What to do
- Upgrade VMware Server to 1.0.10 build 203137 or 2.0.2 build 203138, and apply the ESX/ESXi fixes referenced in VMSA-2009-0015.
- If patching is not immediately possible, restrict network access to the affected VMware management and service interfaces to trusted hosts only.
- Retire or isolate end-of-life VMware Server 1.x/2.x and ESX/ESXi 3.x hosts, which no longer receive current security support.
- Review file system permissions on the host so that the service account cannot read sensitive files outside its required paths.
Detection
- Monitor web and service logs on VMware hosts for requests containing traversal sequences such as ../ or encoded variants.
- Alert on unexpected reads of sensitive files (for example /etc/passwd, host configuration or credential stores) by VMware service processes.
- Use file integrity monitoring on host configuration and credential files to detect anomalous access.
- Hunt for outbound connections from VMware hosts to unknown destinations that could indicate exfiltration of read files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3733 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3733), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.