vulnerability

VMware Workstation: VMware Workstation installer DLL hijacking issue (VMSA-2016-0014) (CVE-2016-7085)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Oct 24, 2016
Added
Oct 24, 2016
Modified
Mar 30, 2026

Description

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

Solution

vmware-workstation-upgrade-12_5_0
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.