Vmware Workstation vulnerabilities
225 known vulnerabilities affecting vmware/workstation.
Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15
Vulnerabilities
Page 1 of 12
CVE-2025-22224P1HIGHCVSS 8.2KEVRansomware≥ 17.0, < 17.6.3≥ 17.x, < 17.6.32025-03-04
CVE-2025-22224 [HIGH] CWE-367 CVE-2025-22224: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads t
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2025-22226P1MEDIUMCVSS 6.0KEVRansomware≥ 17.0, < 17.6.32025-03-04
CVE-2025-22226 [MEDIUM] CWE-125 CVE-2025-22226: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-o
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2019-5526P2HIGHCVSS 7.8ExploitedPoC≥ 15.0.0, < 15.1.02019-05-15
CVE-2019-5526 [HIGH] CWE-427 CVE-2019-5526: VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are im
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.
nvd
CVE-2009-2267P2MEDIUMCVSS 6.9ExploitedPoCv6.5.0v6.5.1+1 more2009-11-02
CVE-2009-2267 [MEDIUM] CVE-2009-2267: VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, V
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is
nvd
CVE-2024-22255P1HIGHCVSS 7.1ExploitedRansomware≥ 17.0.0, < 17.5.12024-03-05
CVE-2024-22255 [HIGH] CWE-770 CVE-2024-22255: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2024-22253P1MEDIUMCVSS 6.7ExploitedRansomware≥ 17.0.0, < 17.5.12024-03-05
CVE-2024-22253 [MEDIUM] CWE-416 CVE-2024-22253: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on
nvd
CVE-2024-22252P1MEDIUMCVSS 6.7ExploitedRansomware≥ 17.0.0, < 17.5.12024-03-05
CVE-2024-22252 [MEDIUM] CWE-416 CVE-2024-22252: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on
nvd
CVE-2017-5753P2MEDIUMCVSS 5.6PoC≥ 12.0.0, < 12.5.82018-01-04
CVE-2017-5753 [MEDIUM] CWE-203 CVE-2017-5753: Systems with microprocessors utilizing speculative execution and branch prediction may allow unautho
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoC≥ 6.5.0, < 6.5.5≥ 7.1, < 7.1.22010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2017-4901P2CRITICALCVSS 9.9PoCv12.0v12.0.1+6 more2017-06-08
CVE-2017-4901 [CRITICAL] CWE-119 CVE-2017-4901: The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x bef
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
nvd
CVE-2012-3569P2CRITICALCVSS 9.3PoCv8.0v8.0.0.18997+5 more2012-11-14
CVE-2012-3569 [CRITICAL] CWE-134 CVE-2012-3569: Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x bef
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.
nvd
CVE-2009-3732P2CRITICALCVSS 10.0PoC≥ 6.5.0, < 6.5.4v7.02010-04-12
CVE-2009-3732 [CRITICAL] CWE-134 CVE-2009-3732: Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allo
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2008-3892P3CRITICALCVSS 10.0PoC≥ 5.5, < 5.5.8≥ 6.0, < 6.0.52008-09-03
CVE-2008-3892 [CRITICAL] CVE-2008-3892: Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server
nvd
CVE-2018-5511P3HIGHCVSS 7.2PoCv14.1.52018-04-13
CVE-2018-5511 [HIGH] CWE-470 CVE-2018-5511: On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
nvd
CVE-2019-5512P3HIGHCVSS 8.8PoC≥ 14.0.0, < 14.1.6≥ 15.0.0, < 15.0.32019-04-09
CVE-2019-5512 [HIGH] CVE-2019-5512: VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM c
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation of privilege.
nvd
CVE-2007-0063P3CRITICALCVSS 10.0≥ 5.5, < 5.5.5≥ 6.0, < 6.0.12007-09-21
CVE-2007-0063 [CRITICAL] CWE-191 CVE-2007-0063: Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x befo
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a m
nvd
CVE-2010-4297P3HIGHCVSS 7.2PoCv6.5.0v6.5.1+8 more2010-12-06
CVE-2010-4297 [HIGH] CWE-20 CVE-2010-4297: The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX
nvd
CVE-2025-41236P2CRITICALCVSS 9.3≥ 17.x, < 17.6.42025-07-15
CVE-2025-41236 [CRITICAL] CWE-787 CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtua
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
nvd
CVE-2017-4933P3HIGHCVSS 8.8v12.x before 12.5.82017-12-20
CVE-2017-4933 [HIGH] CWE-787 CVE-2017-4933: VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x bef
VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap corruption. Successful exploitation of this issue could result in remote code execution in a virt
nvd
CVE-2017-4941P3HIGHCVSS 8.8≥ 12.0.0, < 12.5.8v12.x before 12.5.82017-12-20
CVE-2017-4941 [HIGH] CWE-119 CVE-2017-4941: VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12
VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. Successful exploitation of this issue could result in remote code execution in a virtua
nvd
1 / 12Next →