CVE-2017-4915: High severity vmware workstation and esxi vulnerability
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4915?
CVE-2017-4915 has a medium severity rating due to its potential for privilege escalation on a Linux host.
How do I fix CVE-2017-4915?
To fix CVE-2017-4915, update to the latest version of VMware Workstation Pro or Player that addresses this vulnerability.
Who is affected by CVE-2017-4915?
Users of VMware Workstation Pro and VMware Workstation Player version 12.0.0 on Linux are affected by CVE-2017-4915.
Can CVE-2017-4915 lead to remote exploitation?
No, CVE-2017-4915 requires local access to the host to exploit the privilege escalation vulnerability.
What systems are at risk from CVE-2017-4915?
Linux systems running VMware Workstation Pro or Player version 12.0.0 are at risk from CVE-2017-4915.