CVE-2014-2384 describes a denial-of-service vulnerability in the vmx86.sys driver of VMware Workstation and Player on Windows, allowing a local user to crash the system via a crafted IOCTL call. This vulnerability has a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), indicating a low-complexity local attack that can lead to a complete loss of availability. Despite the potential for system crashes, the vendor deemed the issue non-exploitable, and there is no known public exploit code, Metasploit modules, or evidence of active exploitation. Community discussion and media coverage for this CVE are also non-existent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.1_build_1379776CPE matchmatch criteria | cpe:2.3:a:vmware:player:6.0.1_build_1379776:*:*:*:*:*:*:* | ||
10.0.1_build_1379776CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:10.0.1_build_1379776:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.