CVE-2017-4950: Integer Overflow
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4950?
CVE-2017-4950 has been rated as important due to the potential for out-of-bound reads and code execution.
How do I fix CVE-2017-4950?
To remediate CVE-2017-4950, update VMware Fusion and Workstation to the latest version where the vulnerability has been addressed.
Which versions of VMware are affected by CVE-2017-4950?
CVE-2017-4950 affects VMware Fusion versions from 8.0 to 10.1.1 and VMware Workstation versions from 12.0 to 14.1.1.
Does CVE-2017-4950 affect macOS Yosemite?
CVE-2017-4950 does not affect macOS Yosemite as it is not a vulnerable configuration.
Is IPv6 mode in VMware NAT enabled by default, considering CVE-2017-4950?
IPv6 mode for VMNAT is not enabled by default, which reduces the risk associated with CVE-2017-4950 unless explicitly activated.