Arbitrary Code Execution Vulnerability in VMware Workstation Pro and Player
CVE-2016-7084

7.8HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
29 December 2016

Summary

An identified vulnerability in VMware Workstation Pro and Player versions earlier than 12.5.0 allows guest operating system users to execute arbitrary code on the host system or cause denial of service by exploiting the Cortado ThinPrint virtual printing feature with a specially crafted JPEG 2000 image. This security concern emphasizes the importance of promptly updating these products to mitigate risks associated with unauthorized access or system instability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.