CVE-2017-4898

4 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 70.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 13

Description

VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages3 packages

NVDvmware/workstation_player6 versions+5
CVEListV5vmware/workstation_pro/player12.x prior to version 12.5.3
NVDvmware/workstation_pro6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fgmh-44jq-vhhq: VMware Workstation Pro/Player 122022-05-13
CVEList
CVE-2017-4898: VMware Workstation Pro/Player 122017-06-07

💥Exploits & PoCs

1
Exploit-DB
US Zip Codes Database - 'state' SQL Injection2017-10-30
CVE-2017-4898 (HIGH CVSS 8.8) | VMware Workstation Pro/Player 12.x | cvebase.io