CVE-2009-2628

CWE-94Code Injection3 documents3 sources
Severity
9.3CRITICAL
EPSS
12.8%
top 5.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 2

Description

The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might allow remote attackers to execute arbitrary code via a crafted AVI file that triggers heap memory corruption.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDvmware/player2.5, 2.5.1, 2.5.2+2
NVDvmware/workstation4 versions+3
NVDvmware/ace2.5.0, 2.5.1, 2.5.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-678r-9fw4-2w76: The VMnc media codec in vmnc2022-05-02
CVEList
CVE-2009-2628: The VMnc media codec in vmnc2009-09-08
CVE-2009-2628 (CRITICAL CVSS 9.3) | The VMnc media codec in vmnc.dll in | cvebase.io