Untrusted Search Path Vulnerability in VMware Tools Affecting VMware Products
CVE-2016-5330
7.8HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 8 August 2016
Summary
An untrusted search path vulnerability exists in the HGFS (Shared Folders) feature of VMware Tools, which can allow local users to exploit the system. This vulnerability affects various versions of VMware ESXi, VMware Workstation, and VMware Fusion, enabling the potential execution of malicious DLL files. Attackers can leverage this flaw to gain unauthorized privileges by deploying Trojan horse DLLs located in the current working directory. Consequently, it is essential for users and administrators to apply relevant patches and evaluate their systems to mitigate the associated risks.
References
EPSS Score
28% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved