Vulnerability Description
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMware Tools 10.2.0 is consumed by Workstation 14.1.0 and Fusion 10.1.0 by default.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Workstation | 12.0.0 |
| Vmware | Fusion | 8.0 |
| Apple | Mac Os X | - |
References
- http://www.securityfocus.com/bid/102441Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040109Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040136Third Party AdvisoryVDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2018-0003.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/102441Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040109Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040136Third Party AdvisoryVDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2018-0003.htmlPatchVendor Advisory
FAQ
What is CVE-2017-4945?
CVE-2017-4945 is a vulnerability with a CVSS score of 5.5 (MEDIUM). VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be ...
How severe is CVE-2017-4945?
CVE-2017-4945 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-4945?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Workstation, Vmware Fusion, Apple Mac Os X.