Vulnerability record · CVE-2012-3569 · published 14 November 2012
CVE-2012-3569: VMware OVF Tool format string allows code execution via crafted OVF
Vmware · Ovf Tool
VMware OVF Tool 2.1 on Windows, as shipped with Workstation 8.x before 8.0.5 and Player 4.x before 4.0.5, contains a format string vulnerability (CWE-134). A crafted OVF file can trigger memory corruption that leads to arbitrary code execution in the context of the user opening the file.
Description
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 base score of 9.3 with complete impact and a high EPSS percentile, but exploitation requires user interaction and no KEV listing or known in-the-wild campaign is recorded.
What it is
VMware OVF Tool 2.1 on Windows, as shipped with Workstation 8.x before 8.0.5 and Player 4.x before 4.0.5, contains a format string vulnerability (CWE-134). A crafted OVF file can trigger memory corruption that leads to arbitrary code execution in the context of the user opening the file.
Impact
An attacker who convinces a user to open a malicious OVF file can execute arbitrary code with that user's privileges, giving full compromise of confidentiality, integrity and availability on the affected host.
Attack surface
The flaw is reached over the network in the sense that the malicious OVF file can be delivered remotely, but exploitation requires user interaction: the victim must open the crafted file with the vulnerable OVF Tool or bundled product. No authentication is required by the attacker.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded; EPSS is high (0.477, ~98.8th percentile), and public references include a Packet Storm advisory, indicating proof-of-concept detail is publicly available.
What to do
- Upgrade to VMware Workstation 8.0.5 or later, VMware Player 4.0.5 or later, and OVF Tool 2.1.1 or later per VMSA-2012-0015.
- If immediate patching is not possible, restrict use of OVF Tool and OVF import to trusted files and trusted sources.
- Block or scan inbound OVF/OVA files at email and web gateways before they reach endpoints with the vulnerable tooling.
- Remove or disable OVF Tool on hosts that do not require it, reducing the exposed attack surface.
Detection
- Monitor for OVF Tool or Workstation/Player processes spawning unexpected child processes or making unusual network connections after an OVF file is opened.
- Alert on OVF/OVA files received from external sources and correlate with subsequent execution of ovftool.exe or vmware-vmx.exe.
- Search endpoint logs for crashes or abnormal terminations of OVF Tool when processing externally sourced OVF files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3569 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3569), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.