CVE-2009-3732

VMware ACE 2.5.0-2.5.3 - Remote Code Execution via Format String Vulnerability

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3732. PoCs published by Alexey Sintsov.

AI-analyzed exploit summary The advisory describes a format string vulnerability in VMware Remote Console Plug-in (CVE-2009-3732), which can be exploited via malformed shortcut parameters or a crafted HTML page using ActiveX. Exploitation may lead to arbitrary code execution on the system where VMrc is installed.

Description

Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Alexey Sintsov · textdosmultiple
https://www.exploit-db.com/exploits/12188

The advisory describes a format string vulnerability in VMware Remote Console Plug-in (CVE-2009-3732), which can be exploited via malformed shortcut parameters or a crafted HTML page using ActiveX. Exploitation may lead to arbitrary code execution on the system where VMrc is installed.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: VMware Remote Console Plug-in (e.x.p build-158248)
No auth needed
Prerequisites: User interaction required (e.g., clicking a malicious shortcut or visiting a crafted HTML page) · VMware Remote Console Plug-in installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201209-25.xml
Mailing List, Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2010/000090.html
Broken Link mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39110
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2010-0007.html
Broken Link mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html

Scores

EPSS 0.1620
EPSS Percentile 96.5%

Details

CWE
CWE-134
Status published
Products (7)
vmware/ace 2.6
vmware/ace 2.5.0 - 2.5.4
vmware/player 3.0
vmware/player 2.5.0 - 2.5.4
vmware/server 2.0.0 - 2.0.2
vmware/workstation 7.0
vmware/workstation 6.5.0 - 6.5.4
Published Apr 12, 2010
Tracked Since Feb 18, 2026