Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-4905

Severity
5.5MEDIUM
EPSS
3.4%
top 12.51%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 7
Latest updateMay 13

Description

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

NVDvmware/fusion8.0.08.5.6
NVDvmware/fusion_pro8.0.08.5.6
NVDvmware/workstation_player12.0.012.5.5
CVEListV5vmware/fusion_pro_/_fusion8.x prior to 8.5.6
CVEListV5vmware/workstation_pro_/_player12.x prior to 12.5.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vv24-23fc-h8gh: VMware ESXi 62022-05-13
CVEList
CVE-2017-4905: VMware ESXi 62017-06-07

💥Exploits & PoCs

1
Exploit-DB
VMware WorkStation 12.5.3 - Virtual Machine Escape2019-06-06
CVE-2017-4905 (MEDIUM CVSS 5.5) | VMware ESXi 6.5 without patch ESXi6 | cvebase.io