CVE-2017-4901
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
- Affected products
- Vmware Fusion, Vmware Workstation
- Vmware Fusion
- = 8.0.0, 8.0.1, 8.0.2, 8.1.0, 8.1.1, 8.5.0, 8.5.1, 8.5.2, 8.5.3, 8.5.4
- Vmware Workstation
- = 12.0, 12.0.1, 12.1, 12.1.1, 12.5, 12.5.1, 12.5.2, 12.5.3
- Fix
- Available
- CVSS 3.0
- 9.9 CRITICAL
- EPSS
- 19.9% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-06-08
CVE-2017-4901 at NVD
5 known exploits for CVE-2017-4901
Proof-of-concept code and exploit modules indexed by Sploitus