Vulnerable Systems:
* VMWare Workstation version 6.5.3 build 185404
Immune Systems:
* VMWare Workstation version 6.5.4 build 246459
The vulnerabilities are caused by two integer truncation errors in vmnc.dll when processing HexTile encoded video chunks and can be exploited to cause heap-based buffer overflows.
Successful exploitation may allow execution of arbitrary code by tricking a user into opening a specially crafted AVI file.