First published: Wed Jun 07 2017(Updated: )
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation and ESXi | =12.0.0 | |
VMware Workstation and ESXi | =12.0.1 | |
VMware Workstation and ESXi | =12.1.0 | |
VMware Workstation and ESXi | =12.5.0 | |
VMware Workstation and ESXi | =12.5.1 | |
VMware Workstation and ESXi | =12.5.2 | |
VMware Workstation | =12.0.0 | |
VMware Workstation | =12.0.1 | |
VMware Workstation | =12.1.0 | |
VMware Workstation | =12.5.0 | |
VMware Workstation | =12.5.1 | |
VMware Workstation | =12.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4900 has a severity rating that indicates it can lead to crashing virtual machines.
To fix CVE-2017-4900, upgrade VMware Workstation Pro/Player to version 12.5.3 or higher.
CVE-2017-4900 affects VMware Workstation Pro/Player versions 12.0.0 through 12.5.2.
Yes, CVE-2017-4900 can be exploited by attackers with normal user privileges.
CVE-2017-4900 is a NULL pointer dereference vulnerability found in the SVGA driver.