VULNERABILITY INTELLIGENCE
CVE-2012-3288
CVSS score9.3 HIGH
EPSS probability3.84%
CISA KEVNot currently listed
Published2012-06-14
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Description
VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary code on the host OS or cause a denial of service (memory corruption) on the host OS via a crafted Checkpoint file.
Weakness classification
- CWE-20: Improper Input Validation
Primary references
- cve@mitre.org — Vendor Advisory
- cve@mitre.org
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108