CVE-2012-3289
published 2012-06-14CVE-2012-3289: VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.66%
74.0th percentile
VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to cause a denial of service (guest OS crash) via crafted traffic from a remote virtual device.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted products and ESXi and ESX patches address security issues
vendor_vmware·2012-06-14·CVSS 9.3
CVE-2012-3288 [CRITICAL] VMware hosted products and ESXi and ESX patches address security issues
VMSA-2012-0011: VMware hosted products and ESXi and ESX patches address security issues
Input data is not properly validated when loading Checkpoint files. This may allow an attacker with the ability to load a specially crafted Checkpoint file to execute arbitrary code on the host.
CVEs: CVE-2012-3288, CVE-2012-3289
Affected products: ESXi, VMware Fusion, VMware Tools, VMware Workstation
GHSA
GHSA-f3vw-hmc2-2j8x: VMware Workstation 8
ghsa_unreviewed·2022-05-17
CVE-2012-3289 [HIGH] CWE-94 GHSA-f3vw-hmc2-2j8x: VMware Workstation 8
VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to cause a denial of service (guest OS crash) via crafted traffic from a remote virtual device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-06-14
Published