CVE-2017-4901: Buffer Overflow
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4901?
CVE-2017-4901 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-4901?
To fix CVE-2017-4901, upgrade VMware Workstation to version 12.5.4 or later, and VMware Fusion to version 8.5.5 or later.
What software versions are affected by CVE-2017-4901?
CVE-2017-4901 affects VMware Workstation versions prior to 12.5.4 and VMware Fusion versions prior to 8.5.5.
What types of systems does CVE-2017-4901 affect?
CVE-2017-4901 affects systems running VMware Workstation and VMware Fusion with specific vulnerable versions.
Can CVE-2017-4901 allow unauthorized access?
Yes, CVE-2017-4901 can allow an attacker to execute arbitrary code on the host operating system, potentially leading to unauthorized access.