vulnerability
VMware Workstation: VMware Workstation installer DLL hijacking issue (VMSA-2016-0014) (CVE-2016-7085)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Oct 24, 2016 | Oct 24, 2016 | Mar 30, 2026 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Oct 24, 2016
Added
Oct 24, 2016
Modified
Mar 30, 2026
Description
Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Solution
vmware-workstation-upgrade-12_5_0
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.