CVE-2012-2450
Status: ModifiedHigh (9)—
VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
- Base score: 9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.46%
- Percentile among all scored CVEs: 84
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (5)
CWEs
- NVD-CWE-Other
References
- http://osvdb.org/81695
- http://secunia.com/advisories/49032
- http://www.securityfocus.com/bid/53369
- http://www.securitytracker.com/id?1027019
- http://www.vmware.com/security/advisories/VMSA-2012-0009.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75377
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16852
- http://osvdb.org/81695
- http://secunia.com/advisories/49032
- http://www.securityfocus.com/bid/53369
- http://www.securitytracker.com/id?1027019
- http://www.vmware.com/security/advisories/VMSA-2012-0009.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75377
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16852
Raw JSON (NVD)
Show
{
"id": "CVE-2012-2450",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-05-04T16:55:01.577",
"references": [
{
"url": "http://osvdb.org/81695",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/49032",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/53369",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1027019",
"source": "cve@mitre.org"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2012-0009.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75377",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16852",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/81695",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49032",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/53369",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1027019",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2012-0009.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75377",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16852",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS."
},
{
"lang": "es",
"value": "VMware Workstation v8.x antes de v8.0.3, VMware Player v4.x antes de v4.0.3 VMware Fusion v4.x, antes de v4.1.2, VMware ESXi v3.5 hasta v5.0 y VMware ESX v3.5 hasta v4.1 no registra correctamente los dispositivos SCSI, lo que permite a los usuarios invitados del sistema operativo causar una denegación de servicio (operación de escritura no válida y caída del proceso VMX) o posiblemente ejecutar código arbitrario en el sistema operativo anfitrión mediante el aprovechamiento de privilegios de administrador en el sistema operativo invitado."
}
],
"lastModified": "2026-06-16T23:41:34.910",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:workstation:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCE22BB0-F375-4883-BF6C-5A6369694EF3"
},
{
"criteria": "cpe:2.3:a:vmware:workstation:8.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD913295-9302-425A-A9E1-B0DF76AD3069"
},
{
"criteria": "cpe:2.3:a:vmware:workstation:8.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51B6CAE2-A396-40C8-8FF0-D9EC64D5C9A0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:player:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "535E3D3C-76A5-405A-8F9D-21A86ED31D07"
},
{
"criteria": "cpe:2.3:a:vmware:player:4.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D09D7FB-78EE-4168-996D-FD3CF2E187BD"
},
{
"criteria": "cpe:2.3:a:vmware:player:4.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "816F1646-A1C9-4E4A-BCE1-A34D00B51ABE"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:fusion:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60234129-7F7F-49FA-A425-CDAB4D09AB23"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:4.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4FB73EC4-F3CE-428B-BA40-47FB21181543"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:4.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "927863C2-5A61-4137-83AC-6CF3F2958941"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F74559CB-6E52-421F-88F3-739913C26C8E"
},
{
"criteria": "cpe:2.3:a:vmware:fusion:4.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4870DAA2-6670-47EF-BF74-6E39B92E75DB"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FAE88D8C-9CC3-46D1-9F26-290BC679F47E"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:3.5:1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58ED8AB4-0FDF-4752-B44E-56F58593CE41"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13771B15-CD71-472A-BE56-718B87D5825D"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.0:1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A4E41C0-31FA-47AA-A9BF-B9A6C1D44801"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.0:2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF016EE7-083A-4D62-A6D4-2807EB47B6DB"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.0:3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F11844A-3C6C-4AA5-87DC-979AFF62867A"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.0:4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC463653-A599-45CF-8EA9-8854D5C59963"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BDE707D-A1F4-4829-843E-F6633BB84D6D"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.1:1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DC5C2BF-6EC6-436F-A925-469E87249C8A"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:4.1:2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BCE5DA9-BB88-4169-B77C-40B1F98D511A"
},
{
"criteria": "cpe:2.3:o:vmware:esxi:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2331236-2E9B-4B52-81EE-B52DEB41ACE5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:vmware:esx:3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFF29100-E124-4416-95CF-18B4246D43F2"
},
{
"criteria": "cpe:2.3:o:vmware:esx:3.5:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37A5D726-3D38-44D5-B509-1B8B003903A0"
},
{
"criteria": "cpe:2.3:o:vmware:esx:3.5:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4DA3B20-A743-4F37-A095-65161FFBEB73"
},
{
"criteria": "cpe:2.3:o:vmware:esx:3.5:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF7C3C65-BE63-407E-9CFD-E571025C3E79"
},
{
"criteria": "cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC337BB7-9A45-4406-A783-851F279130EE"
},
{
"criteria": "cpe:2.3:o:vmware:esx:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B6BA46F-4E8C-4B2A-AE92-81B9F1B4D56C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}