7.8
CVSSv3

CVE-2016-7085

Published: 29/12/2016 Updated: 30/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x prior to 12.5.0 and VMware Workstation Player 12.x prior to 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware workstation player 12.0.0

vmware workstation player 12.0.1

vmware workstation player 12.1.0

vmware workstation player 12.1.1

vmware workstation pro 12.0.0

vmware workstation pro 12.0.1

vmware workstation pro 12.1.0

vmware workstation pro 12.1.1

Mailing Lists

Hi @ll, on February 13, 2016, I sent a vulnerability report regarding the then current executable installer of VMware-player 713 to its vendor On September 14, 2016, VMware published <blogsvmwarecom/security/2016/09/vmsa-2016-0014html> and <wwwvmwarecom/security/advisories/VMSA-2016-0014html> I was NOT AMUSED t ...