peter bassill · operator
$ cve CVE-2016-5330 JSON

CVE-2016-5330 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 18% (pctl 97)

Patch early

A public exploit exists.

Description

Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS18.02% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-426
On CISA KEVno
Public exploityes
Published2016-08-08
Last modified2026-06-17

Affected (7)

VendorProduct
applemac os x
microsoftwindows
vmwareesxi
vmwarefusion
vmwaretools
vmwareworkstation player
vmwareworkstation pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD