CVE-2017-4903
published 2017-06-07CVE-2017-4903: VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch…
PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.41%
33.2th percentile
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have an uninitialized stack memory usage in SVGA. This issue may allow a guest to execute code on the host.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 8.0.0 < 8.5.6 | 8.5.6 |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | >= 8.0.0 < 8.5.6 | 8.5.6 |
| vmware | fusion_pro_fusion | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | >= 12.0.0 < 12.5.5 | 12.5.5 |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | >= 12.0.0 < 12.5.5 | 12.5.5 |
| vmware | workstation_pro_player | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation and Fusion updates address critical and moderate security issues
vendor_vmware·2017-03-28·CVSS 8.8
CVE-2017-4902 [HIGH] VMware ESXi, Workstation and Fusion updates address critical and moderate security issues
VMSA-2017-0006: VMware ESXi, Workstation and Fusion updates address critical and moderate security issues
a. ESXi, Workstation, Fusion SVGA memory corruption ESXi, Workstation, Fusion have a heap buffer overflow and uninitialized stack memory usage in SVGA. These issues may allow a guest to execute code on the host. VMware would like to thank ZDI and Team 360 Security from Qihoo for reporting these issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2017-4902 (heap issue) and CVE-2017-4903 (stack issue) to these issues. Note: ESXi 6.0 is affected by CVE-2017-4903 but not by CVE-2017-4902. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Pr
GHSA
GHSA-9q76-gqr4-73cm: VMware ESXi 6
ghsa_unreviewed·2022-05-13
CVE-2017-4903 [HIGH] CWE-119 GHSA-9q76-gqr4-73cm: VMware ESXi 6
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have an uninitialized stack memory usage in SVGA. This issue may allow a guest to execute code on the host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/97160http://www.securitytracker.com/id/1038148http://www.securitytracker.com/id/1038149http://www.vmware.com/security/advisories/VMSA-2017-0006.htmlhttp://www.securityfocus.com/bid/97160http://www.securitytracker.com/id/1038148http://www.securitytracker.com/id/1038149http://www.vmware.com/security/advisories/VMSA-2017-0006.html
2017-06-07
Published