cbcvebase.
CVE-2017-4905
published 2017-06-07

CVE-2017-4905: VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EXPLOIT
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.

Affected

20 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion>= 8.0.0 < 8.5.68.5.6
vmwarefusion_pro
vmwarefusion_pro>= 8.0.0 < 8.5.68.5.6
vmwarefusion_pro_fusion
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_workstation
vmwareworkstation_player
vmwareworkstation_player>= 12.0.0 < 12.5.512.5.5
vmwareworkstation_pro
vmwareworkstation_pro>= 12.0.0 < 12.5.512.5.5
vmwareworkstation_pro_player