CVE-2012-4897

medium
Published 2012-10-05 · Modified 2026-04-29
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.vmware.com/security/advisories/VMSA-2012-0014.html

Application impact

VendorProductVersionsFixed
vmwaremovie_decoder{"endIncluding":"7.1.2"}
vmwaremovie_decoder6.5.2
vmwaremovie_decoder6.5.3
vmwaremovie_decoder6.5.4
vmwaremovie_decoder6.5.5
vmwaremovie_decoder7.0

References

Verify integrity in audit chain (admin only). AS-IS.