CVE-2012-3569: VMware Ovf Tool

High severity, CVSS 9.3. EPSS: 47.7% chance of exploitation in the next 30 days.

Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.

Affected products

  • VMware Ovf Tool: version 2.1 only
  • VMware Player: version 4.0 only; version 4.0.0.18997 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only
  • VMware Workstation: version 8.0 only; version 8.0.0.18997 only; version 8.0.1 only; version 8.0.1.27038 only; version 8.0.2 only; version 8.0.3 only; …

Published 2012-11-14. Last modified 2026-06-16.