Vulnerable Systems:
* VMware Workstation versions prior to 6.5.4 build 246459
* VMware Player versions prior to 2.5.4 build 246459
* VMware Server versions 2.x
* VMware Movie Decoder versions prior to 6.5.4 Build 246459
Immune Systems:
* VMware Workstation version 6.5.4 build 246459
* VMware Player version 2.5.4 build 246459
* VMware Movie Decoder version 6.5.4 Build 246459
The flaw is caused by a heap overflow error in the VMnc media codec when processing malformed AVI files, which could be exploited by attackers to potentially execute arbitrary code by tricking a user into opening a malicious movie file.