CVE-2012-3569 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 47.7% (pctl 99)
Patch early
A public exploit exists.
Description
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 47.72% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-11-14 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | windows |
| vmware | ovf tool |
| vmware | player |
| vmware | workstation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | VMware OVF Tools - Format String (Metasploit) (2) | 2013-02-12 |
| exploit-db | VMware OVF Tools - Format String (Metasploit) (1) | 2013-02-06 |
References
- http://osvdb.org/87117
- http://packetstormsecurity.com/files/120101/VMWare-OVF-Tools-Format-String.html
- http://secunia.com/advisories/51240
- http://technet.microsoft.com/en-us/security/msvr/msvr13-002
- http://www.vmware.com/security/advisories/VMSA-2012-0015.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79922
- http://osvdb.org/87117
- http://packetstormsecurity.com/files/120101/VMWare-OVF-Tools-Format-String.html
- http://secunia.com/advisories/51240
- http://technet.microsoft.com/en-us/security/msvr/msvr13-002
- http://www.vmware.com/security/advisories/VMSA-2012-0015.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79922
→ the Explorer · watch your stack · NVD