CVE-2016-7083 describes a critical heap buffer overflow vulnerability in VMware Workstation Pro and Player versions 12.x prior to 12.5.0 on Windows, specifically when Cortado ThinPrint virtual printing is enabled. This flaw allows a low-privileged guest OS user to execute arbitrary code on the host OS or trigger a denial of service through memory corruption by embedding malicious TrueType fonts within EMFSPOOL data. With a CVSS v3 score of 7.8 (HIGH), this vulnerability has a local attack vector and high impact on confidentiality, integrity, and availability, but requires high attack complexity. While not listed in CISA's KEV catalog, a proof-of-concept exploit is publicly available on ExploitDB, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_player:12.0.0:*:*:*:*:*:*:* | ||
12.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_player:12.0.1:*:*:*:*:*:*:* | ||
12.1.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_player:12.1.0:*:*:*:*:*:*:* | ||
12.1.1CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_player:12.1.1:*:*:*:*:*:*:* | ||
12.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_pro:12.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.