CVE-2016-5329 is a kernel information disclosure vulnerability affecting VMware Fusion 8.x on OS X with System Integrity Protection (SIP) enabled. This flaw allows a local attacker to determine kernel memory addresses, thereby bypassing the kernel Address Space Layout Randomization (kASLR) protection mechanism. Rated Medium with a CVSS score of 5.5, it requires local access and has a high impact on confidentiality, but no impact on integrity or availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, suggesting it is not actively exploited. While there are a few community discussions and media mentions, overall attention is low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.0.0:*:*:*:*:*:*:* | ||
8.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.0.1:*:*:*:*:*:*:* | ||
8.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.0.2:*:*:*:*:*:*:* | ||
8.1.0CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.1.0:*:*:*:*:*:*:* | ||
8.1.1CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.