Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
http://www.vmware.com/security/advisories/VMSA-2016-0014.html | vendor advisory |
http://www.securitytracker.com/id/1036805 | vdb entry |
http://www.securityfocus.com/bid/92940 | third party advisory vdb entry |