CVE-2016-5330 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 18% (pctl 97)
Patch early
A public exploit exists.
Description
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 18.02% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-426 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-08-08 |
| Last modified | 2026-06-17 |
Affected (7)
| Vendor | Product |
|---|---|
| apple | mac os x |
| microsoft | windows |
| vmware | esxi |
| vmware | fusion |
| vmware | tools |
| vmware | workstation player |
| vmware | workstation pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | VMware Host Guest Client Redirector - DLL Side Loading (Metasploit) | 2016-08-06 |
References
- http://www.rapid7.com/db/modules/exploit/windows/misc/vmhgfs_webdav_dll_sideload
- http://www.securityfocus.com/archive/1/539131/100/0/threaded
- http://www.securityfocus.com/bid/92323
- http://www.securitytracker.com/id/1036544
- http://www.securitytracker.com/id/1036545
- http://www.securitytracker.com/id/1036619
- http://www.vmware.com/security/advisories/VMSA-2016-0010.html
- https://securify.nl/advisory/SFY20151201/dll_side_loading_vulnerability_in_vmware_host_guest_client_redirector.html
- http://www.rapid7.com/db/modules/exploit/windows/misc/vmhgfs_webdav_dll_sideload
- http://www.securityfocus.com/archive/1/539131/100/0/threaded
- http://www.securityfocus.com/bid/92323
- http://www.securitytracker.com/id/1036544
- http://www.securitytracker.com/id/1036545
- http://www.securitytracker.com/id/1036619
- http://www.vmware.com/security/advisories/VMSA-2016-0010.html
- https://securify.nl/advisory/SFY20151201/dll_side_loading_vulnerability_in_vmware_host_guest_client_redirector.html
→ the Explorer · watch your stack · NVD