CVE-2015-2337
Summary
| CVE | CVE-2015-2337 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-13 14:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:A/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | All | All | All | All |
| Application | Vmware | Fusion | 6.0 | All | All | All |
| Application | Vmware | Fusion | 6.0.1 | All | All | All |
| Application | Vmware | Fusion | 6.0.2 | All | All | All |
| Application | Vmware | Fusion | 6.0.3 | All | All | All |
| Application | Vmware | Fusion | 6.0.4 | All | All | All |
| Application | Vmware | Fusion | 6.0.5 | All | All | All |
| Application | Vmware | Fusion | 7.0 | All | All | All |
| Application | Vmware | Fusion | 7.0.1 | All | All | All |
| Application | Vmware | Horizon Client | 3.2.0 | All | All | All |
| Application | Vmware | Horizon Client | 3.3 | All | All | All |
| Application | Vmware | Horizon View Client | 5.4 | All | All | All |
| Application | Vmware | Horizon View Client | 5.4.1 | All | All | All |
| Application | Vmware | Player | 6.0 | All | All | All |
| Application | Vmware | Player | 6.0.1 | All | All | All |
| Application | Vmware | Player | 6.0.2 | All | All | All |
| Application | Vmware | Player | 6.0.3 | All | All | All |
| Application | Vmware | Player | 6.0.4 | All | All | All |
| Application | Vmware | Player | 6.0.5 | All | All | All |
| Application | Vmware | Player | 7.0 | All | All | All |
| Application | Vmware | Player | 7.1 | All | All | All |
| Application | Vmware | Workstation | 10.0 | All | All | All |
| Application | Vmware | Workstation | 10.0.1 | All | All | All |
| Application | Vmware | Workstation | 10.0.2 | All | All | All |
| Application | Vmware | Workstation | 10.0.3 | All | All | All |
| Application | Vmware | Workstation | 10.0.4 | All | All | All |
| Application | Vmware | Workstation | 10.0.5 | All | All | All |
| Application | Vmware | Workstation | 11.0 | All | All | All |
| Application | Vmware | Workstation | 11.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Horizon Client for Windows Bugs Let Local Users Gain Elevated Privileges and Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMSA-2015-0004 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VMware Workstation/Player/Fusion Bugs Let Local Users Gain Elevated Privileges and Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.