CVE-2017-4938: Null Pointer Dereference
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4938?
CVE-2017-4938 has a moderate severity level as it allows for potential denial of service through guest RPC NULL pointer dereference.
How do I fix CVE-2017-4938?
To fix CVE-2017-4938, users should update VMware Workstation to version 12.5.8 or later and VMware Fusion to version 8.5.9 or later.
Who is affected by CVE-2017-4938?
CVE-2017-4938 affects users of VMware Workstation versions 12.x before 12.5.8 and VMware Fusion versions 8.x before 8.5.9.
What type of vulnerability is CVE-2017-4938?
CVE-2017-4938 is classified as a NULL pointer dereference vulnerability within the guest RPC service.
What can happen if CVE-2017-4938 is exploited?
Exploitation of CVE-2017-4938 may allow an attacker to crash their virtual machines.