CVE-2017-4898
published 2017-06-07CVE-2017-4898: VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path…
PriorityP339high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.39%
31.8th percentile
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro_player | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgmh-44jq-vhhq: VMware Workstation Pro/Player 12
ghsa_unreviewed·2022-05-13
CVE-2017-4898 [HIGH] GHSA-fgmh-44jq-vhhq: VMware Workstation Pro/Player 12
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.
VMware
VMware Workstation update addresses multiple security issues
vendor_vmware·2017-03-09·CVSS 8.8
CVE-2017-4898 [HIGH] VMware Workstation update addresses multiple security issues
VMSA-2017-0003: VMware Workstation update addresses multiple security issues
a. VMware Workstation DLL loading vulnerability VMware Workstation Pro/Player contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed. VMware would like to thank Ivil for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4898 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product
No detection rules found.
No writeups or analysis indexed.
2017-06-07
Published