CVE-2012-5459: VMware Player

High severity, CVSS 7.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."

Affected products

  • VMware Player: version 4.0 only; version 4.0.0.18997 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only
  • VMware Workstation: version 8.0 only; version 8.0.0.18997 only; version 8.0.1 only; version 8.0.1.27038 only; version 8.0.2 only; version 8.0.3 only; …

Published 2012-11-14. Last modified 2026-06-16.