Vulnerability Details CVE-2015-2337
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.2%
CVSS Severity
CVSS v2 Score 5.8
Products affected by CVE-2015-2337
-
cpe:2.3:a:vmware:fusion:6.0
-
cpe:2.3:a:vmware:fusion:6.0.1
-
cpe:2.3:a:vmware:fusion:6.0.2
-
cpe:2.3:a:vmware:fusion:6.0.3
-
cpe:2.3:a:vmware:fusion:6.0.4
-
cpe:2.3:a:vmware:fusion:6.0.5
-
cpe:2.3:a:vmware:fusion:7.0
-
cpe:2.3:a:vmware:fusion:7.0.1
-
cpe:2.3:a:vmware:horizon_client:3.2.0
-
cpe:2.3:a:vmware:horizon_client:3.3
-
cpe:2.3:a:vmware:horizon_view_client:5.4
-
cpe:2.3:a:vmware:horizon_view_client:5.4.1
-
cpe:2.3:a:vmware:player:6.0
-
cpe:2.3:a:vmware:player:6.0.1
-
cpe:2.3:a:vmware:player:6.0.2
-
cpe:2.3:a:vmware:player:6.0.3
-
cpe:2.3:a:vmware:player:6.0.4
-
cpe:2.3:a:vmware:player:6.0.5
-
cpe:2.3:a:vmware:player:7.0
-
cpe:2.3:a:vmware:player:7.1
-
cpe:2.3:a:vmware:workstation:10.0
-
cpe:2.3:a:vmware:workstation:10.0.1
-
cpe:2.3:a:vmware:workstation:10.0.2
-
cpe:2.3:a:vmware:workstation:10.0.3
-
cpe:2.3:a:vmware:workstation:10.0.4
-
cpe:2.3:a:vmware:workstation:10.0.5
-
cpe:2.3:a:vmware:workstation:11.0
-
cpe:2.3:a:vmware:workstation:11.1
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:microsoft:windows:1.0
-
cpe:2.3:o:microsoft:windows:2.0
-
cpe:2.3:o:microsoft:windows:2000
-
cpe:2.3:o:microsoft:windows:3.0
-
cpe:2.3:o:microsoft:windows:3.1
-
cpe:2.3:o:microsoft:windows:3.11
-
cpe:2.3:o:microsoft:windows:server_2008
-
cpe:2.3:o:microsoft:windows:vista