First published: Fri Nov 17 2017(Updated: )
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation | =12.0.0 | |
VMware Workstation | =12.0.1 | |
VMware Workstation | =12.1 | |
VMware Workstation | =12.1.1 | |
VMware Workstation | =12.5 | |
VMware Workstation | =12.5.1 | |
VMware Workstation | =12.5.2 | |
VMware Workstation | =12.5.3 | |
VMware Workstation | =12.5.4 | |
VMware Workstation | =12.5.5 | |
VMware Workstation | =12.5.6 | |
VMware Workstation | =12.5.7 | |
VMware Fusion Pro | =8.0.0 | |
VMware Fusion Pro | =8.0.1 | |
VMware Fusion Pro | =8.0.2 | |
VMware Fusion Pro | =8.1.0 | |
VMware Fusion Pro | =8.1.1 | |
VMware Fusion Pro | =8.5.0 | |
VMware Fusion Pro | =8.5.1 | |
VMware Fusion Pro | =8.5.2 | |
VMware Fusion Pro | =8.5.3 | |
VMware Fusion Pro | =8.5.4 | |
VMware Fusion Pro | =8.5.5 | |
VMware Fusion Pro | =8.5.6 | |
VMware Fusion Pro | =8.5.7 | |
VMware Fusion Pro | =8.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-4934 is classified as high due to the potential for a guest to execute arbitrary code on the host system.
To fix CVE-2017-4934, update VMware Workstation to version 12.5.8 or higher and VMware Fusion to version 8.5.9 or higher.
CVE-2017-4934 affects VMware Workstation versions 12.x up to 12.5.7 and VMware Fusion versions 8.x up to 8.5.8.
CVE-2017-4934 is a heap buffer overflow vulnerability that can allow code execution from a guest on the host.
Yes, CVE-2017-4934 can potentially be exploited remotely if the vulnerable software is configured improperly.