CVE-2016-7461
VMware Security Advisory 2016-0019
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
La función de arrastrar y soltar (también conocida como DnD) en VMware Workstation Pro 12.x en versiones anteriores a 12.5.2 y VMware Workstation Player 12.x en versiones anteriores a 12.5.2 y VMware Fusion y Fusion Pro 8.x en versiones anteriores a 8.5.2 permite a usuarios invitados de SO ejecutar código arbitrario en el SO anfitrión o provocar una denegación de servicio (acceso a memoria fuera de límites en el SO anfitrión) a través de vectores no especificados.
VMware Workstation and Fusion updates address a critical out-of-bounds memory access vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-09-09 CVE Reserved
- 2016-11-14 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94280 | Third Party Advisory | |
http://www.securitytracker.com/id/1037282 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.vmware.com/security/advisories/VMSA-2016-0019.html | 2017-07-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.0.0 Search vendor "Vmware" for product "Fusion" and version "8.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.0.1 Search vendor "Vmware" for product "Fusion" and version "8.0.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.0.2 Search vendor "Vmware" for product "Fusion" and version "8.0.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.1.0 Search vendor "Vmware" for product "Fusion" and version "8.1.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.1.1 Search vendor "Vmware" for product "Fusion" and version "8.1.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.5.0 Search vendor "Vmware" for product "Fusion" and version "8.5.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Search vendor "Vmware" for product "Fusion" | 8.5.1 Search vendor "Vmware" for product "Fusion" and version "8.5.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.0.0 Search vendor "Vmware" for product "Fusion Pro" and version "8.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.0.1 Search vendor "Vmware" for product "Fusion Pro" and version "8.0.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.0.2 Search vendor "Vmware" for product "Fusion Pro" and version "8.0.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.1.0 Search vendor "Vmware" for product "Fusion Pro" and version "8.1.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.1.1 Search vendor "Vmware" for product "Fusion Pro" and version "8.1.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.5.0 Search vendor "Vmware" for product "Fusion Pro" and version "8.5.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Fusion Pro Search vendor "Vmware" for product "Fusion Pro" | 8.5.1 Search vendor "Vmware" for product "Fusion Pro" and version "8.5.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Player Search vendor "Vmware" for product "Workstation Player" | 12.0.0 Search vendor "Vmware" for product "Workstation Player" and version "12.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Player Search vendor "Vmware" for product "Workstation Player" | 12.0.1 Search vendor "Vmware" for product "Workstation Player" and version "12.0.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Player Search vendor "Vmware" for product "Workstation Player" | 12.1.0 Search vendor "Vmware" for product "Workstation Player" and version "12.1.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Player Search vendor "Vmware" for product "Workstation Player" | 12.1.1 Search vendor "Vmware" for product "Workstation Player" and version "12.1.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Player Search vendor "Vmware" for product "Workstation Player" | 12.5.0 Search vendor "Vmware" for product "Workstation Player" and version "12.5.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Player Search vendor "Vmware" for product "Workstation Player" | 12.5.1 Search vendor "Vmware" for product "Workstation Player" and version "12.5.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Pro Search vendor "Vmware" for product "Workstation Pro" | 12.0.0 Search vendor "Vmware" for product "Workstation Pro" and version "12.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Pro Search vendor "Vmware" for product "Workstation Pro" | 12.0.1 Search vendor "Vmware" for product "Workstation Pro" and version "12.0.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Pro Search vendor "Vmware" for product "Workstation Pro" | 12.1.0 Search vendor "Vmware" for product "Workstation Pro" and version "12.1.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Pro Search vendor "Vmware" for product "Workstation Pro" | 12.1.1 Search vendor "Vmware" for product "Workstation Pro" and version "12.1.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Pro Search vendor "Vmware" for product "Workstation Pro" | 12.5.0 Search vendor "Vmware" for product "Workstation Pro" and version "12.5.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Vmware Search vendor "Vmware" | Workstation Pro Search vendor "Vmware" for product "Workstation Pro" | 12.5.1 Search vendor "Vmware" for product "Workstation Pro" and version "12.5.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|