CVE-2016-7461 describes a critical vulnerability in VMware Workstation Pro, Workstation Player, and Fusion/Fusion Pro versions 12.x and 8.x respectively, where the drag-and-drop function allows a guest OS user to execute arbitrary code or cause a denial of service on the host OS. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and it's not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, suggesting it is known within security circles. Its FAUCET Risk Score of 67/100 further emphasizes its significant risk despite the lack of confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.0.0:*:*:*:*:*:*:* | ||
8.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.0.1:*:*:*:*:*:*:* | ||
8.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.0.2:*:*:*:*:*:*:* | ||
8.1.0CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.1.0:*:*:*:*:*:*:* | ||
8.1.1CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:8.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.