Medium
VMware Tools for Windows could allow a local authenticated attacker to obtain sensitive information, caused by improper handling of XML external entity (XXE) declarations. By using a specially-crafted XML content, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service condition
Refer to VMware Security Advisory for patch, upgrade or suggested workaround information.