Vulnerability Description
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Fusion | 8.0.0 |
| Vmware | Workstation | 12.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96881Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038025
- https://www.vmware.com/security/advisories/VMSA-2017-0005.htmlVendor Advisory
- http://www.securityfocus.com/bid/96881Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038025
- https://www.vmware.com/security/advisories/VMSA-2017-0005.htmlVendor Advisory
FAQ
What is CVE-2017-4901?
CVE-2017-4901 is a vulnerability with a CVSS score of 9.9 (CRITICAL). The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execut...
How severe is CVE-2017-4901?
CVE-2017-4901 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-4901?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Fusion, Vmware Workstation.