CVE-2017-4925: Null Pointer Dereference
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4925?
CVE-2017-4925 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2017-4925?
To fix CVE-2017-4925, ensure that you apply the appropriate patches for the affected VMware ESXi, Workstation, or Fusion products.
Which versions of VMware are affected by CVE-2017-4925?
CVE-2017-4925 affects VMware ESXi versions 5.5, 6.0, and 6.5, along with VMware Workstation versions prior to 12.5.3 and Fusion prior to 8.5.4.
What kind of issue does CVE-2017-4925 represent?
CVE-2017-4925 represents a NULL pointer dereference vulnerability.
Who is impacted by CVE-2017-4925?
Organizations utilizing specific versions of VMware ESXi, Workstation, or Fusion without the latest patches are impacted by CVE-2017-4925.