CVE-2017-4945: Medium severity vmware workstation and esxi vulnerability
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMware Tools 10.2.0 is consumed by Workstation 14.1.0 and Fusion 10.1.0 by default.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4945?
CVE-2017-4945 is considered a moderate severity vulnerability affecting VMware Workstation and Fusion.
How do I fix CVE-2017-4945?
To fix CVE-2017-4945, update VMware Tools to version 10.2.0 or later for each affected VM.
Which products are affected by CVE-2017-4945?
CVE-2017-4945 affects VMware Workstation 12.x and 14.x as well as VMware Fusion 8.x and 10.x.
What type of vulnerability is CVE-2017-4945?
CVE-2017-4945 is a guest access control vulnerability that may allow unauthorized program execution.
When was CVE-2017-4945 disclosed?
CVE-2017-4945 was disclosed in 2017, highlighting vulnerabilities in multiple versions of VMware products.