CVE-2017-4905
published 2017-06-07CVE-2017-4905: VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch…
PriorityP429medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EXPLOIT
EPSS
1.20%
64.7th percentile
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 8.0.0 < 8.5.6 | 8.5.6 |
| vmware | fusion_pro | — | — |
| vmware | fusion_pro | >= 8.0.0 < 8.5.6 | 8.5.6 |
| vmware | fusion_pro_fusion | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | >= 12.0.0 < 12.5.5 | 12.5.5 |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | >= 12.0.0 < 12.5.5 | 12.5.5 |
| vmware | workstation_pro_player | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation and Fusion updates address critical and moderate security issues
vendor_vmware·2017-03-28·CVSS 8.8
CVE-2017-4902 [HIGH] VMware ESXi, Workstation and Fusion updates address critical and moderate security issues
VMSA-2017-0006: VMware ESXi, Workstation and Fusion updates address critical and moderate security issues
a. ESXi, Workstation, Fusion SVGA memory corruption ESXi, Workstation, Fusion have a heap buffer overflow and uninitialized stack memory usage in SVGA. These issues may allow a guest to execute code on the host. VMware would like to thank ZDI and Team 360 Security from Qihoo for reporting these issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2017-4902 (heap issue) and CVE-2017-4903 (stack issue) to these issues. Note: ESXi 6.0 is affected by CVE-2017-4903 but not by CVE-2017-4902. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Pr
GHSA
GHSA-vv24-23fc-h8gh: VMware ESXi 6
ghsa_unreviewed·2022-05-13
CVE-2017-4905 [MEDIUM] CWE-908 GHSA-vv24-23fc-h8gh: VMware ESXi 6
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/97164http://www.securitytracker.com/id/1038148http://www.securitytracker.com/id/1038149http://www.vmware.com/security/advisories/VMSA-2017-0006.htmlhttp://www.securityfocus.com/bid/97164http://www.securitytracker.com/id/1038148http://www.securitytracker.com/id/1038149http://www.vmware.com/security/advisories/VMSA-2017-0006.html
2017-06-07
Published