CVE-2015-3650: High severity vmware player vulnerability
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3650?
CVE-2015-3650 has a moderate severity rating due to its potential for local privilege escalation.
How do I fix CVE-2015-3650?
To fix CVE-2015-3650, update to the latest versions of VMware Workstation, Player, or Horizon Client as specified in the relevant security advisories.
Which VMware products are affected by CVE-2015-3650?
CVE-2015-3650 affects VMware Workstation versions 7.x to 10.x, VMware Player versions 5.x to 6.x, and Horizon Client 5.x local-mode.
Is there a workaround for CVE-2015-3650?
Currently, there are no known workarounds for CVE-2015-3650 aside from applying the available updates.
What type of vulnerability is CVE-2015-3650?
CVE-2015-3650 is classified as a local privilege escalation vulnerability in VMware products.