← Vulnerability feed

Vulnerability record · CVE-2016-7461 · published 29 December 2016

CVE-2016-7461: Vmware fusion memory buffer overflow vulnerability

Vmware · Fusion

The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.

8.8 CVSS 3.0 High EPSS 0.54% · top 56.7% CWE-119 · Memory buffer overflow
8.8CVSS 3.0 base score, v2 7.2
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-7461 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-3950VMware Fusion, VMRC and Horizon Client setuid privilege escalationVMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affec…KEVEPSS 7.3%analysed6.0CVE-2025-22226VMware ESXi, Workstation and Fusion HGFS out-of-bounds read leaks vmx memoryVMware ESXi, Workstation, Fusion and related cloud products contain an out-of-bounds read in the HGFS (Host Guest File System) component. A malicious…KEVEPSS 1.8%analysed9.9CVE-2017-4901Vmware fusion memory buffer overflow vulnerabilityThe drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acc…EPSS 20%9.6CVE-2019-5521Vmware fusion out-of-bounds read vulnerabilityVMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (1…EPSS 1.6%9.3CVE-2012-3288Vmware workstation improper input validation vulnerabilityVMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware…EPSS 3.8%9.3CVE-2011-3868Vmware workstation memory buffer overflow vulnerabilityBuffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remot…EPSS 5.8%9.1CVE-2019-5541Vmware workstation out-of-bounds write vulnerabilityVMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network ad…EPSS 1.4%9.0CVE-2012-2449Vmware workstation memory buffer overflow vulnerabilityVMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2016-7461), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.