Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-0199


Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).


Published

2009-09-08T22:30:00.217

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware ace 2.5.0 Yes
Application vmware ace 2.5.1 Yes
Application vmware ace 2.5.2 Yes
Application vmware movie_decoder 6.5.3 Yes
Application vmware player 2.5 Yes
Application vmware player 2.5.1 Yes
Application vmware player 2.5.2 Yes
Application vmware player 2.5.2_build_156735 Yes
Application vmware workstation 6.5 Yes
Application vmware workstation 6.5.0 Yes
Application vmware workstation 6.5.1 Yes
Application vmware workstation 6.5.2 Yes

References