CVE-2016-7461
published 2016-12-29CVE-2016-7461: The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion…
PriorityP344high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.54%
42.0th percentile
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9cw2-r87q-mc5v: The drag-and-drop (aka DnD) function in VMware Workstation Pro 12
ghsa_unreviewed·2022-05-17
CVE-2016-7461 [HIGH] CWE-119 GHSA-9cw2-r87q-mc5v: The drag-and-drop (aka DnD) function in VMware Workstation Pro 12
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
VMware
VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability
vendor_vmware·2016-11-13·CVSS 8.8
CVE-2016-7461 [HIGH] VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability
VMSA-2016-0019: VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability
a. VMware Workstation and Fusion out-of-bounds memory access vulnerability The drag-and-drop (DnD) function in VMware Workstation and Fusion has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
CVEs: CVE-2016-7461
Affected products: ESXi, Fusion Pro, VMware Fusion, VMware Workstation, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-12-29
Published