CVE-2016-2077: VMware Player

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via unspecified vectors.

Affected products

  • VMware Player: version 7.0 only; version 7.1 only; version 7.1.1 only; version 7.1.2 only
  • VMware Workstation: version 11.0 only; version 11.1 only; version 11.1.1 only; version 11.1.2 only

Published 2016-05-18. Last modified 2026-06-17.