7.2
CVSSv2

CVE-2016-7461

Published: 29/12/2016 Updated: 28/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.8 | Impact Score: 6 | Exploitability Score: 2
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x prior to 12.5.2 and VMware Workstation Player 12.x prior to 12.5.2 and VMware Fusion and Fusion Pro 8.x prior to 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware fusion_pro 8.1.1

vmware fusion_pro 8.5.0

vmware fusion 8.5.0

vmware fusion 8.5.1

vmware workstation_pro 12.0.0

vmware workstation_player 12.0.1

vmware fusion_pro 8.0.2

vmware fusion_pro 8.1.0

vmware fusion 8.1.0

vmware fusion 8.1.1

vmware workstation_pro 12.0.1

vmware workstation_pro 12.1.1

vmware workstation_pro 12.1.0

vmware fusion_pro 8.5.1

vmware fusion 8.0.0

vmware workstation_player 12.5.0

vmware workstation_player 12.5.1

vmware workstation_player 12.1.1

vmware workstation_player 12.1.0

vmware fusion_pro 8.0.0

vmware fusion_pro 8.0.1

vmware fusion 8.0.1

vmware fusion 8.0.2

vmware workstation_pro 12.5.0

vmware workstation_pro 12.5.1

vmware workstation_player 12.0.0