Input validation error in vSphere Client - CVE-2014-1209
Published: April 11, 2014 / Updated: August 10, 2020
vSphere Client
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.