CVE-2016-7081
Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- vmware/workstation player · vmware/workstation pro
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/92935Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036805
- http://www.vmware.com/security/advisories/VMSA-2016-0014.htmlVendor Advisory
- http://www.securityfocus.com/bid/92935Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036805
- http://www.vmware.com/security/advisories/VMSA-2016-0014.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.