CVE-2016-7083 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 1.5% (pctl 73)
Patch early
A public exploit exists.
Description
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via TrueType fonts embedded in EMFSPOOL.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 1.5% — more likely to be exploited than 73% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-12-29 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | windows |
| vmware | workstation player |
| vmware | workstation pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC) | 2016-09-19 |
References
- http://www.securityfocus.com/bid/92934
- http://www.securitytracker.com/id/1036805
- http://www.vmware.com/security/advisories/VMSA-2016-0014.html
- https://www.exploit-db.com/exploits/40398/
- http://www.securityfocus.com/bid/92934
- http://www.securitytracker.com/id/1036805
- http://www.vmware.com/security/advisories/VMSA-2016-0014.html
- https://www.exploit-db.com/exploits/40398/
→ the Explorer · watch your stack · NVD