CVE-2012-1516

CRITICAL

VMware ESX and ESXi 3.5-4.1 - Memory Corruption via RPC Command Handling

Title source: llm
STIX 2.1

Description

The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving data pointers.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027018
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53369

Scores

CVSS v3 9.9
EPSS 0.0158
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (6)
vmware/esx 3.5 (4 CPE variants)
vmware/esx 4.0
vmware/esx 4.1
vmware/esxi 3.5 (2 CPE variants)
vmware/esxi 4.0 (5 CPE variants)
vmware/esxi 4.1
Published May 04, 2012
Tracked Since Feb 18, 2026