Workstation
Vendor:
First CVE: Jun 26, 1999 · Active for 27 years
219
Total CVEs
More Total CVEs than 100% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Workstation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 1999
27 years ago
Most Recent CVE
Feb 27, 2026
147 days ago
CVE Severity & Scoring
Workstation219 CVEs
39%
52%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local76 (34.7%)
Network29 (13.2%)
Unknown111 (50.7%)
Physical2 (0.9%)
Adjacent Network1 (0.5%)
Attack Complexity
Low83 (37.9%)
High25 (11.4%)
Unknown111 (50.7%)
User Interaction
None102 (46.6%)
Unknown111 (50.7%)
Required6 (2.7%)
Privileges Required
Low69 (31.5%)
High22 (10.0%)
None17 (7.8%)
Unknown111 (50.7%)
Top CVEs
Signals from CVEs in this product scope (219 CVEs).
219 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2012-3569HIGH Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assis | Nov 14, 2012 | 9.3 | 74 | NO | YES |
CVE-2025-22224HIGH VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2010-1205CRITICAL Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG | Jun 30, 2010 | 9.8 | 67 | NO | YES |
CVE-2025-22226MEDIUM VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir | Mar 4, 2025 | 6.0 | 62 | YES | NO |
CVE-2017-4901CRITICAL The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may all | Jun 8, 2017 | 9.9 | 54 | NO | YES |
CVE-2009-3732HIGH Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors. | Apr 12, 2010 | 10.0 | 48 | NO | YES |
CVE-2008-3892HIGH Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player | Sep 3, 2008 | 10.0 | 48 | NO | YES |
CVE-2013-1662MEDIUM vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted ls | Aug 24, 2013 | 6.9 | 44 | NO | YES |
CVE-2018-5511HIGH On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Con | Apr 13, 2018 | 7.2 | 41 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (219 CVEs).
CISA KEV
2 CVEs
0.9% of CVEs· 96th percentile
Metasploit
2 CVEs
0.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
8.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (219 CVEs).
Media Mentions
Signals from CVEs in this product scope (219 CVEs).
Top CNAs Publishing CVEs For Workstation
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.2 | 3 | 7.3 | 1.8% | 0 | 1 |
| 9.0.1 | 3 | 7.3 | 1.8% | 0 | 1 |
| 9.0 | 5 | 6.5 | 1.4% | 0 | 2 |
| 8.0.6 | 1 | 6.9 | 4.6% | 0 | 1 |
| 8.0.5 | 1 | 6.9 | 4.6% | 0 | 1 |
| 8.0.4 | 5 | 7.9 | 10.9% | 0 | 3 |
| 8.0.3 | 7 | 8.1 | 8.6% | 0 | 3 |
| 8.0.2 | 10 | 8.2 | 6.6% | 0 | 4 |
| 8.0.1.27038 | 6 | 7.8 | 9.2% | 0 | 4 |
| 8.0.1 | 11 | 8.2 | 6.2% | 0 | 4 |
| 8.0.0.18997 | 6 | 7.8 | 9.2% | 0 | 4 |
| 8.0 | 11 | 8.2 | 6.2% | 0 | 4 |
| 7.1.5 | 1 | 9.3 | 3.8% | 0 | 0 |
| 7.1.4.16648 | 1 | 9.3 | 3.8% | 0 | 0 |
| 7.1.4 | 2 | 9.3 | 4.8% | 0 | 0 |
| 7.1.3 | 6 | 6.8 | 1.8% | 0 | 0 |
| 7.1.2 | 10 | 7.1 | 2.3% | 0 | 1 |
| 7.1.1 | 11 | 6.7 | 2.1% | 0 | 1 |
| 7.1 | 8 | 7.3 | 2.8% | 0 | 1 |
| 7.0.1 | 10 | 6.8 | 3.6% | 0 | 2 |