First published: Wed Jun 07 2017(Updated: )
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation Player | =12.0.0 | |
VMware Workstation Player | =12.0.1 | |
VMware Workstation Player | =12.1.0 | |
VMware Workstation Player | =12.5.0 | |
VMware Workstation Player | =12.5.1 | |
VMware Workstation Player | =12.5.2 | |
VMware Workstation Pro | =12.0.0 | |
VMware Workstation Pro | =12.0.1 | |
VMware Workstation Pro | =12.1.0 | |
VMware Workstation Pro | =12.5.0 | |
VMware Workstation Pro | =12.5.1 | |
VMware Workstation Pro | =12.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.