CVE-2017-4907
published 2017-06-08CVE-2017-4907: VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow…
PriorityP356critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.76%
88.6th percentile
VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | horizon_client | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | unified_access_gateway | — | — |
| vmware | vmware_horizon | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Unified Access Gateway, Horizon View and Workstation updates resolve multiple security vulnerabilities
vendor_vmware·2017-04-18·CVSS 9.8
CVE-2017-4907 [CRITICAL] VMware Unified Access Gateway, Horizon View and Workstation updates resolve multiple security vulnerabilities
VMSA-2017-0008: VMware Unified Access Gateway, Horizon View and Workstation updates resolve multiple security vulnerabilities
a. Unified Access Gateway and Horizon View heap buffer-overflow vulnerability VMware Unified Access Gateway and Horizon View contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway. VMware would like to thank Claudio Moletta (redr2e) for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4907 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch Mitigation/
GHSA
GHSA-3f8w-p3m8-mpjx: VMware Unified Access Gateway (2
ghsa_unreviewed·2022-05-17
CVE-2017-4907 [CRITICAL] CWE-119 GHSA-3f8w-p3m8-mpjx: VMware Unified Access Gateway (2
VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-08
Published