9.3

CVE-2012-3288

VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary code on the host OS or cause a denial of service (memory corruption) on the host OS via a crafted Checkpoint file.

Data is provided by the National Vulnerability Database (NVD)
VMwareWorkstation Version7.0
VMwareWorkstation Version7.0.1
VMwareWorkstation Version7.1
VMwareWorkstation Version7.1.1
VMwareWorkstation Version7.1.2
VMwareWorkstation Version7.1.3
VMwareWorkstation Version7.1.4
VMwareWorkstation Version7.1.4.16648
VMwareWorkstation Version7.1.5
VMwareWorkstation Version8.0
VMwareWorkstation Version8.0.1
VMwareWorkstation Version8.0.2
VMwareWorkstation Version8.0.3
VMwarePlayer Version3.0
VMwarePlayer Version3.0.1
VMwarePlayer Version3.1
VMwarePlayer Version3.1.1
VMwarePlayer Version3.1.2
VMwarePlayer Version3.1.3
VMwarePlayer Version3.1.4
VMwarePlayer Version3.1.5
VMwarePlayer Version4.0
VMwarePlayer Version4.0.1
VMwarePlayer Version4.0.2
VMwarePlayer Version4.0.3
VMwareFusion Version4.0
VMwareFusion Version4.0.1
VMwareFusion Version4.0.2
VMwareFusion Version4.1
VMwareFusion Version4.1.1
VMwareFusion Version4.1.2
VMwareEsx Version3.5
VMwareEsx Version3.5 Updateupdate1
VMwareEsx Version3.5 Updateupdate2
VMwareEsx Version3.5 Updateupdate3
VMwareEsx Version4.0
VMwareEsx Version4.1
VMwareESXi Version3.5
VMwareESXi Version3.5 Update1
VMwareESXi Version4.0
VMwareESXi Version4.0 Update1
VMwareESXi Version4.0 Update2
VMwareESXi Version4.0 Update3
VMwareESXi Version4.0 Update4
VMwareESXi Version4.1
VMwareESXi Version4.1 Update1
VMwareESXi Version4.1 Update2
VMwareESXi Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.03% 0.821
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.