CVE-2016-7461
8.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD
Description
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
Affected (26)
Products: Vmware: Fusion, Fusion Pro, Workstation Player, Workstation Pro
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0.0 | |
| Version 8.0.0 | |
| Version 12.0.0 | |
| Version 12.0.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (6)
Source: security@vmware.com
Source: security@vmware.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.