VMware Fusion 8.1.x < 8.1.1 Shared Folders (HGFS) Guest DLL Hijacking Arbitrary Code Execution (VMSA-2016-0010)

High Nessus Plugin ID 92943


A virtualization application installed on the remote Mac OS X host is affected by an arbitrary code execution vulnerability.


The version of VMware Fusion installed on the remote Mac OS X host is 8.1.x prior to 8.1.1. It is, therefore, affected by an arbitrary code execution vulnerability in the Shared Folders (HGFS) feature due to improper loading of Dynamic-link library (DLL) files from insecure paths, including the current working directory, which may not be under user control. A remote attacker can exploit this vulnerability, by placing a malicious DLL in the path or by convincing a user into opening a file on a network share, to inject and execute arbitrary code in the context of the current user.


Upgrade to VMware Fusion 8.1.1 or later.

Note that VMware Tools on Windows-based guests that use the Shared Folders (HGFS) feature must also be updated to completely mitigate the vulnerability.

See Also


Plugin Details

Severity: High

ID: 92943

File Name: macosx_fusion_vmsa_2016_0010.nasl

Version: $Revision: 1.5 $

Type: local

Agent: macosx

Published: 2016/08/12

Modified: 2016/11/28

Dependencies: 50828

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 9.6

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:X

Vulnerability Information

CPE: cpe:/a:vmware:fusion

Required KB Items: Host/local_checks_enabled, installed_sw/VMware Fusion

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/08/04

Vulnerability Publication Date: 2016/08/04

Exploitable With

Metasploit (DLL Side Loading Vulnerability in VMware Host Guest Client Redirector)

Reference Information

CVE: CVE-2016-5330

BID: 92323

OSVDB: 142634

VMSA: 2016-0010