CVE-2017-4901
published 2017-06-08CVE-2017-4901: The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access…
PriorityP272critical9.9CVSS 3.0
AVNACLPRLUINSCCHIHAH
EXPLOIT
EPSS
19.94%
97.1th percentile
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro_fusion | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via the drag-and-drop (DnD) function in VMware Workstation/Fusion; monitor for anomalous DnD-related activity originating from guest VMs that may indicate out-of-bounds memory access attempts against the host process. ↗
- ·Two distinct exploit variants exist targeting different patch levels: one for versions before 12.5.3 (EDB-47715) and one for versions before 12.5.5 (EDB-47714); both were tested on build 4638234 (12.5.2). ↗
CVSS provenance
nvdv3.09.9CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8xg8-8x73-gmmx: The drag-and-drop (DnD) function in VMware Workstation 12
ghsa_unreviewed·2022-05-17
CVE-2017-4901 [CRITICAL] CWE-119 GHSA-8xg8-8x73-gmmx: The drag-and-drop (DnD) function in VMware Workstation 12
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
VMware
VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability
vendor_vmware·2017-03-14·CVSS 9.9
CVE-2017-4901 [CRITICAL] VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability
VMSA-2017-0005: VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability
a. VMware Workstation and Fusion out-of-bounds memory access vulnerability The drag-and-drop (DnD) function in VMware Workstation and Fusion has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
CVEs: CVE-2017-4901
Affected products: ESXi, Fusion Pro, VMware Fusion, VMware Workstation, Workstation Player, Workstation Pro
No detection rules found.
Exploit-DB
VMware WorkStation 12.5.3 - Virtual Machine Escape
exploitdb·2019-06-06·CVSS 5.5
CVE-2017-4905 [MEDIUM] VMware WorkStation 12.5.3 - Virtual Machine Escape
VMware WorkStation 12.5.3 - Virtual Machine Escape
---
# VMware Escape Exploit
VMware Escape Exploit before VMware WorkStation 12.5.3
Host Target: Win10 x64
Compiler: VS2013
Test on VMware 12.5.2 build-4638234
# Known issues
* Failing to heap manipulation causes host process crash. (About 50% successful rate )
* Not quite elaborate because I'm not good at doing heap "fengshui" on winows LFH.
# FAQ
* Q: Error in reboot vmware after crashing process.
* A: Just remove ***.lck** folder in your vm directory or wait a while and have a coffee :).Here is a simple [script](https://raw.githubusercontent.com/unamer/vmware_escape/master/cve-2017-4901/cleanvm.bat) I used to clean up.
# Reference
* https://keenlab.tencent.com/en/2018/04/23/A-bunch-of-Red-Pills-VMware-Escapes/
EDB Note: Dow
Exploit-DB
VMware WorkStation 12.5.5 - Virtual Machine Escape
exploitdb·2017-08-08
CVE-2017-4901 VMware WorkStation 12.5.5 - Virtual Machine Escape
VMware WorkStation 12.5.5 - Virtual Machine Escape
---
# VMware Escape Exploit
VMware Escape Exploit before VMware WorkStation 12.5.5
Host Target: Win10 x64
Compiler: VS2013
Test on VMware 12.5.2 build-4638234
# Known issues
* Failing to heap manipulation causes host process crash.
* Not quite elaborate because I'm not good at doing heap "fengshui" on winows LFH.
# FAQ
* Q: Error in reboot vmware after crashing process.
* A: Just remove ***.lck** folder in your vm directory or wait a while and have a coffee :).Here is a simple [script](https://raw.githubusercontent.com/unamer/vmware_escape/master/cve-2017-4901/cleanvm.bat) I used to clean up.
EDB Note ~ Download: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/47714.zip
No writeups or analysis indexed.
2017-06-08
Published