Vmware Workstation vulnerabilities
225 known vulnerabilities affecting vmware/workstation.
Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15
Vulnerabilities
Page 9 of 12
CVE-2022-22938P4MEDIUMCVSS 6.5≥ 16.0.0, < 16.2.22022-01-28
CVE-2022-22938 [MEDIUM] CVE-2022-22938: VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contai
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a denial-of-service condition in the Thin
nvd
CVE-2020-3999P4MEDIUMCVSS 6.5≥ 15.0.0, < 15.5.72020-12-21
CVE-2020-3999 [MEDIUM] CWE-20 CVE-2020-3999: VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual
nvd
CVE-2024-22269P4MEDIUMCVSS 6.0≥ 17.0.0, < 17.5.22024-05-14
CVE-2024-22269 [MEDIUM] CWE-200 CVE-2024-22269: VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth devi
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
nvd
CVE-2023-34044P4MEDIUMCVSS 6.0≥ 17.0.0, < 17.5≥ 17.x, < 17.52023-10-20
CVE-2023-34044 [MEDIUM] CWE-125 CVE-2023-34044: VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds rea
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual
machine may be able to read privileged information contained in
hypervisor
nvd
CVE-2010-2249P4MEDIUMCVSS 6.5≥ 6.5.0, < 6.5.5≥ 7.1, < 7.1.22010-06-30
CVE-2010-2249 [MEDIUM] CWE-401 CVE-2010-2249: Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers t
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
nvd
CVE-2004-2515P4HIGHCVSS 7.2v4.5.2_build_88482004-12-31
CVE-2004-2515 [HIGH] CVE-2004-2515: Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privile
Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already availab
nvd
CVE-2007-2491P4HIGHCVSS 7.2v5.5.3_build_346852007-05-04
CVE-2007-2491 [HIGH] CVE-2007-2491: The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.2
The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to write to arbitrary memory locations via a crafted poke to I/O port 0x1004, triggering a denial of service (virtual machine crash) or other unspecified impact, a related issue to CVE-2007-1337.
nvd
CVE-2008-4915P4MEDIUMCVSS 6.9≥ 5.5, ≤ 5.5.8≥ 6.0, ≤ 6.0.52008-11-10
CVE-2008-4915 [MEDIUM] CWE-264 CVE-2008-4915: The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the
nvd
CVE-2008-1361P4MEDIUMCVSS 6.8v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1361 [MEDIUM] CWE-264 CVE-2008-1361: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation that causes the authd process to connect to an arbitrary named
nvd
CVE-2017-4938P4MEDIUMCVSS 6.5v12.0.0v12.0.1+11 more2017-11-17
CVE-2017-4938 [MEDIUM] CWE-476 CVE-2017-4938: VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL point
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
nvd
CVE-2007-1744P4MEDIUMCVSS 6.3≤ 5.5.32007-05-02
CVE-2007-1744 [MEDIUM] CVE-2007-1744: Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4,
Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.
nvd
CVE-2011-2145P4MEDIUMCVSS 6.3v7.1.1v7.1.2+1 more2011-06-06
CVE-2011-2145 [MEDIUM] CWE-264 CVE-2011-2145: mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, V
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1, when a Solaris or FreeBSD guest OS is used, allows guest OS users to modify arbitrary guest OS files via unspecified vector
nvd
CVE-2015-2339P4MEDIUMCVSS 6.1v10.0v10.0.1+6 more2015-06-13
CVE-2015-2339 [MEDIUM] CVE-2015-2339: TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different
nvd
CVE-2015-2338P4MEDIUMCVSS 6.1v10.0v10.0.1+6 more2015-06-13
CVE-2015-2338 [MEDIUM] CWE-399 CVE-2015-2338: TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a d
nvd
CVE-2010-1138P4MEDIUMCVSS 5.0v7.0v6.5.0+3 more2010-04-12
CVE-2010-1138 [MEDIUM] CWE-200 CVE-2010-1138: The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation
The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware Server 2.x, and VMwa
nvd
CVE-2008-1340P4HIGHCVSS 7.1v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1340 [HIGH] CWE-399 CVE-2008-1340: Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Play
Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption."
nvd
CVE-2010-4295P4MEDIUMCVSS 6.9v7.0v7.0.1+3 more2010-12-06
CVE-2010-4295 [MEDIUM] CWE-362 CVE-2010-4295: Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via vectors involving temporary files.
nvd
CVE-2014-3793P4MEDIUMCVSS 5.8v10.0v10.0.12014-05-31
CVE-2014-3793 [MEDIUM] CVE-2014-3793: VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.
nvd
CVE-2023-20870P4MEDIUMCVSS 6.0≥ 17.0.0, < 17.0.22023-04-25
CVE-2023-20870 [MEDIUM] CWE-125 CVE-2023-20870: VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functio
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
nvd
CVE-2009-4811P4MEDIUMCVSS 5.0v6.5.0v6.5.1+5 more2010-04-27
CVE-2009-4811 [MEDIUM] CVE-2009-4811: VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware W
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x al
nvd