First published: Sat Jun 13 2015(Updated: )
TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors, a different vulnerability than CVE-2012-0897.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion | =6.0 | |
VMware Fusion | =6.0.1 | |
VMware Fusion | =6.0.2 | |
VMware Fusion | =6.0.3 | |
VMware Fusion | =6.0.4 | |
VMware Fusion | =6.0.5 | |
VMware Fusion | =7.0 | |
VMware Fusion | =7.0.1 | |
VMware Player | =6.0 | |
VMware Player | =6.0.1 | |
VMware Player | =6.0.2 | |
VMware Player | =6.0.3 | |
VMware Player | =6.0.4 | |
VMware Player | =6.0.5 | |
VMware Player | =7.0 | |
VMware Player | =7.1 | |
VMware Workstation | =10.0 | |
VMware Workstation | =10.0.1 | |
VMware Workstation | =10.0.2 | |
VMware Workstation | =10.0.3 | |
VMware Workstation | =10.0.4 | |
VMware Workstation | =10.0.5 | |
VMware Workstation | =11.0 | |
VMware Workstation | =11.1 | |
Vmware Horizon Client | =3.2.0 | |
Vmware Horizon Client | =3.3 | |
Vmware Horizon View Client | =5.4 | |
Vmware Horizon View Client | =5.4.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2336 is rated as important, indicating a significant impact on system security.
To fix CVE-2015-2336, you should update to the latest version of VMware Workstation, Player, or Horizon Client as specified by VMware.
CVE-2015-2336 affects VMware Workstation 10.x and 11.x, VMware Player 6.x and 7.x, and VMware Horizon Client versions before the respective patched versions.
CVE-2015-2336 is a memory allocation vulnerability that can lead to code execution within the guest operating system.
Users of affected versions of VMware products running on Windows are at risk from CVE-2015-2336.