CVE-2016-7085

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:vmware:workstation_player:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.1.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:57

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/92940 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92940 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1036805 - () http://www.securitytracker.com/id/1036805 -
References () http://www.vmware.com/security/advisories/VMSA-2016-0014.html - Vendor Advisory () http://www.vmware.com/security/advisories/VMSA-2016-0014.html - Vendor Advisory

Information

Published : 2016-12-29 09:59

Updated : 2024-11-21 02:57


NVD link : CVE-2016-7085

Mitre link : CVE-2016-7085

CVE.ORG link : CVE-2016-7085


JSON object : View

Products Affected

vmware

  • workstation_player
  • workstation_pro

microsoft

  • windows
CWE
CWE-426

Untrusted Search Path