CVE-2015-3650

vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
vmwareplayer
5.0
vmwareplayer
5.0.1
vmwareplayer
5.0.2
vmwareplayer
5.0.3
vmwareplayer
5.0.4
vmwareplayer
6.0
vmwareplayer
6.0.1
vmwareplayer
6.0.2
vmwareplayer
6.0.3
vmwareplayer
6.0.4
vmwareplayer
6.0.5
vmwareplayer
6.0.6
vmwareplayer
7.0
vmwareplayer
7.1
vmwareworkstation
10.0
vmwareworkstation
10.0.1
vmwareworkstation
10.0.2
vmwareworkstation
10.0.3
vmwareworkstation
10.0.4
vmwareworkstation
10.0.5
vmwareworkstation
10.0.6
vmwareworkstation
11.0
vmwareworkstation
11.1
vmwarehorizon_view_client
5.4
vmwarehorizon_view_client
5.4.1
𝑥
= Vulnerable software versions