← Back

CVE-2016-7461

nvd nist
Published: Dec 29, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.

Affected (26)

4 products
Fusion
Fusion Pro
Workstation Player
Workstation Pro
Configuration A
26 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Vmware
Version 8.0.0
Version 8.0.1
Version 8.0.2
Version 8.1.0
Version 8.1.1
Version 8.5.0
Version 8.5.1
Vmware
Version 8.0.0
Version 8.0.1
Version 8.0.2
Version 8.1.0
Version 8.1.1
Version 8.5.0
Version 8.5.1
Vmware
Version 12.0.0
Version 12.0.1
Version 12.1.0
Version 12.1.1
Version 12.5.0
Version 12.5.1
Vmware
Version 12.0.0
Version 12.0.1
Version 12.1.0
Version 12.1.1
Version 12.5.0
Version 12.5.1
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (6)

Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.