CVE-2016-5328: VMware Tools

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.

Affected products

  • VMware Tools: up to and including 10.0.8; version 10.0.0 only; version 10.0.5 only; version 10.0.6 only; version 9.0.0 only; version 9.0.1 only; …

Published 2016-12-29. Last modified 2026-06-17.