Vmware Workstation vulnerabilities
225 known vulnerabilities affecting vmware/workstation.
Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15
Vulnerabilities
Page 8 of 12
CVE-2007-1069P4HIGHCVSS 7.8≤ 5.5.32007-05-02
CVE-2007-1069 [HIGH] CVE-2007-1069: The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of servi
The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).
nvd
CVE-2007-1337P4HIGHCVSS 7.8≤ 5.5.32007-05-02
CVE-2007-1337 [HIGH] CVE-2007-1337: The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state in
The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vectors.
nvd
CVE-2026-22722P4MEDIUMCVSS 6.1≥ 17.0, < 25H2u12026-02-26
CVE-2026-22722 [MEDIUM] CWE-476 CVE-2026-22722: A malicious actor with authenticated user privileges on a Windows based Workstation host may be able
A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'
nvd
CVE-2008-2099P4MEDIUMCVSS 6.9v6.02008-06-02
CVE-2008-2099 [MEDIUM] CWE-119 CVE-2008-2099: Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2
Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and VMware ACE 2 before 2.0.2 build 93057 on Windows allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
CVE-2011-1787P4MEDIUMCVSS 6.9v7.1.1v7.1.2+1 more2011-06-06
CVE-2011-1787 [MEDIUM] CWE-362 CVE-2011-1787: Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary d
nvd
CVE-2024-22270P4MEDIUMCVSS 6.0≥ 17.0.0, < 17.5.22024-05-14
CVE-2024-22270 [MEDIUM] CWE-200 CVE-2024-22270: VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
nvd
CVE-2007-1877P4HIGHCVSS 7.8≤ 5.5.32007-05-02
CVE-2007-1877 [HIGH] CVE-2007-1877: VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS b
VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.
nvd
CVE-2022-22983P4MEDIUMCVSS 5.9≥ 16.0.0, < 16.2.42022-08-10
CVE-2022-22983 [MEDIUM] CWE-522 CVE-2022-22983: VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerabili
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected through VMware Workstation.
nvd
CVE-2018-6957P4MEDIUMCVSS 5.3v14.x before 14.1.1v12.x2018-03-15
CVE-2018-6957 [MEDIUM] CWE-772 CVE-2018-6957: VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a deni
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
nvd
CVE-2020-3995P4MEDIUMCVSS 5.3≥ 15.0.0, < 15.1.02020-10-20
CVE-2020-3995 [MEDIUM] CWE-401 CVE-2020-3995: In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak issue resulting in memory resourc
nvd
CVE-2020-3965P4MEDIUMCVSS 5.5≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3965 [MEDIUM] CWE-125 CVE-2020-3965: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
nvd
CVE-2020-3963P4MEDIUMCVSS 5.5≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3963 [MEDIUM] CWE-416 CVE-2020-3963: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in phy
nvd
CVE-2020-3971P4MEDIUMCVSS 5.5≥ 15.0.0, < 15.0.2v15.x before 15.0.22020-06-25
CVE-2020-3971 [MEDIUM] CWE-787 CVE-2020-3971: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged
nvd
CVE-2007-5618P4HIGHCVSS 7.2≥ 5.5, < 5.5.5≥ 6.0, < 6.0.12007-10-21
CVE-2007-5618 [HIGH] CVE-2007-5618: Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
nvd
CVE-2008-1363P4HIGHCVSS 7.2≥ 5.5, < 5.5.6≥ 6.0, < 6.0.32008-03-20
CVE-2008-1363 [HIGH] CWE-264 CVE-2008-1363: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which
nvd
CVE-2008-1362P4HIGHCVSS 7.2v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1362 [HIGH] CVE-2008-1362: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecur
nvd
CVE-2009-1147P4HIGHCVSS 7.2v1.0.1v1.0.2+41 more2009-04-06
CVE-2009-1147 [HIGH] CVE-2009-1147: Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMwar
Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local users to gain privileges via unknown vectors.
nvd
CVE-2008-0923P4MEDIUMCVSS 6.9v4.5.2v5.5.3_build_34685+2 more2008-02-26
CVE-2008-0923 [MEDIUM] CWE-22 CVE-2008-0923: Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Play
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mecha
nvd
CVE-2018-6982P4MEDIUMCVSS 6.5≥ 14.0.0, < 14.1.4v15.0.02018-12-04
CVE-2018-6982 [MEDIUM] CWE-908 CVE-2018-6982: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contai
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
nvd
CVE-2018-6977P4MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.1.5≥ 15.0.0, ≤ 15.0.2+1 more2018-10-09
CVE-2018-6977 [MEDIUM] CWE-835 CVE-2018-6977: VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on th
nvd