CVE-2017-4939: High severity VMware Workstation vulnerability
Published Nov 17, 2017
·Updated
VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary code.
Affected Software
11 affected components
VMware Workstation=12.0.0
VMware Workstation=12.0.1
VMware Workstation=12.1.1
VMware Workstation=12.5.0
VMware Workstation=12.5.1
VMware Workstation=12.5.2
VMware Workstation=12.5.3
VMware Workstation=12.5.4
VMware Workstation=12.5.5
VMware Workstation=12.5.6
VMware Workstation=12.5.7
Event History
Nov 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4939?
CVE-2017-4939 is categorized as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-4939?
To fix CVE-2017-4939, users should upgrade VMware Workstation to version 12.5.8 or later.
3
What versions of VMware Workstation are affected by CVE-2017-4939?
CVE-2017-4939 affects VMware Workstation versions 12.0.0 through 12.5.7.
4
What can attackers do by exploiting CVE-2017-4939?
Exploiting CVE-2017-4939 allows attackers to load malicious DLL files that can execute arbitrary code.
5
Is there a workaround for CVE-2017-4939?
There are no effective workarounds for CVE-2017-4939; upgrading to a patched version is highly recommended.