Vulnerability Description
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Fusion | >= 8.0, < 8.5.10 |
| Apple | Mac Os X | - |
| Vmware | Workstation | >= 12.0, < 12.5.9 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102490Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040161Third Party AdvisoryVDB Entry
- https://www.vmware.com/security/advisories/VMSA-2018-0005.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/102490Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040161Third Party AdvisoryVDB Entry
- https://www.vmware.com/security/advisories/VMSA-2018-0005.htmlPatchVendor Advisory
FAQ
What is CVE-2017-4950?
CVE-2017-4950 is a vulnerability with a CVSS score of 7.0 (HIGH). VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute c...
How severe is CVE-2017-4950?
CVE-2017-4950 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-4950?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Fusion, Apple Mac Os X, Vmware Workstation.