CVE-2015-3650

EUVD-2015-3686
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
vmwareplayer
5.0
vmwareplayer
5.0.1
vmwareplayer
5.0.2
vmwareplayer
5.0.3
vmwareplayer
5.0.4
vmwareplayer
6.0
vmwareplayer
6.0.1
vmwareplayer
6.0.2
vmwareplayer
6.0.3
vmwareplayer
6.0.4
vmwareplayer
6.0.5
vmwareplayer
6.0.6
vmwareplayer
7.0
vmwareplayer
7.1
vmwareworkstation
10.0
vmwareworkstation
10.0.1
vmwareworkstation
10.0.2
vmwareworkstation
10.0.3
vmwareworkstation
10.0.4
vmwareworkstation
10.0.5
vmwareworkstation
10.0.6
vmwareworkstation
11.0
vmwareworkstation
11.1
vmwarehorizon_view_client
5.4
vmwarehorizon_view_client
5.4.1
𝑥
= Vulnerable software versions