peter bassill · operator
$ cve CVE-2012-3569 JSON

CVE-2012-3569 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 47.7% (pctl 99)

Patch early

A public exploit exists.

Description

Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS47.72% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2012-11-14
Last modified2026-06-16

Affected (4)

VendorProduct
microsoftwindows
vmwareovf tool
vmwareplayer
vmwareworkstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD