Untrusted Search Path Vulnerability in VMware Tools Affecting VMware Products
CVE-2016-5330

7.8HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
8 August 2016

Summary

An untrusted search path vulnerability exists in the HGFS (Shared Folders) feature of VMware Tools, which can allow local users to exploit the system. This vulnerability affects various versions of VMware ESXi, VMware Workstation, and VMware Fusion, enabling the potential execution of malicious DLL files. Attackers can leverage this flaw to gain unauthorized privileges by deploying Trojan horse DLLs located in the current working directory. Consequently, it is essential for users and administrators to apply relevant patches and evaluate their systems to mitigate the associated risks.

References

EPSS Score

28% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.