cbcvebase.
CVE-2017-4900
published 2017-06-07

CVE-2017-4900: VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of…

PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.34%
26.0th percentile
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Affected

16 ranges
VendorProductVersion rangeFixed in
vmwarevmware_workstation
vmwareworkstation_player
vmwareworkstation_player
vmwareworkstation_player
vmwareworkstation_player
vmwareworkstation_player
vmwareworkstation_player
vmwareworkstation_player
vmwareworkstation_pro
vmwareworkstation_pro
vmwareworkstation_pro
vmwareworkstation_pro
vmwareworkstation_pro
vmwareworkstation_pro
vmwareworkstation_pro
vmwareworkstation_pro_player

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.