CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

VMware Workstation Pro and Player Multiple Vulnerabilities. (VMSA-2016-0014)

2016年9月21日 1292点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

VMware Workstation is a hosted hypervisor that runs on x64 versions of Windows and Linux operating systems.

A local user on a Windows guest system can trigger a heap overflow in Cortado ThinPrint to execute arbitrary code on the Windows host system running VMware Workstation [CVE-2016-7081]. Systems with virtual printing enabled are affected.
A local user on a Windows guest system can trigger a memory corruption error in Cortado ThinPrint ('tpview.dll') in the processing of EMF files [CVE-2016-7082], TrueType fonts embedded in EMFSPOOL [CVE-2016-7083], and JPEG2000 images [CVE-2016-7084] to execute arbitrary code on the Windows host system running VMware Workstation. Systems with virtual printing enabled are affected.
A local user on the host system can exploit a DLL hijacking flaw to execute arbitrary code on the host system [CVE-2016-7085].

Affected Version
VMware Workstation Pro 12.x.x before 12.5,
VMware Workstation Player 12.x.x before 12.5

漏洞危害

A local user on the guest system can gain elevated privileges on the host system.
A local user on the host system can obtain elevated privileges on the host system.

解决方案

The vendor has issued a fix (Workstation Pro 12.5.0, Player 12.5.0).

Refer to VMSA-2016-0014 for further details.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

VMSA-2016-0014: Windows

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me