CVE-2014-1209: VMware Vsphere Client

High severity, CVSS 9.3. EPSS: 3.8% chance of exploitation in the next 30 days.

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.

Affected products

  • VMware Vsphere Client: version 4.0 only; version 4.1 only; version 5.0 only; version 5.1 only

Published 2014-04-11. Last modified 2026-06-17.