CVE-2017-4909
published 2017-06-08CVE-2017-4909: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF)…
PriorityP337high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
0.37%
29.1th percentile
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | horizon_client | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view_client_for_windows | — | — |
| vmware | vmware_horizon | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Unified Access Gateway, Horizon View and Workstation updates resolve multiple security vulnerabilities
vendor_vmware·2017-04-18·CVSS 9.8
CVE-2017-4907 [CRITICAL] VMware Unified Access Gateway, Horizon View and Workstation updates resolve multiple security vulnerabilities
VMSA-2017-0008: VMware Unified Access Gateway, Horizon View and Workstation updates resolve multiple security vulnerabilities
a. Unified Access Gateway and Horizon View heap buffer-overflow vulnerability VMware Unified Access Gateway and Horizon View contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway. VMware would like to thank Claudio Moletta (redr2e) for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4907 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch Mitigation/
GHSA
GHSA-hh4q-82vf-6xhx: VMware Workstation (12
ghsa_unreviewed·2022-05-17
CVE-2017-4909 [HIGH] CWE-119 GHSA-hh4q-82vf-6xhx: VMware Workstation (12
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/97911http://www.securitytracker.com/id/1038280http://www.securitytracker.com/id/1038281http://www.vmware.com/security/advisories/VMSA-2017-0008.htmlhttp://www.securityfocus.com/bid/97911http://www.securitytracker.com/id/1038280http://www.securitytracker.com/id/1038281http://www.vmware.com/security/advisories/VMSA-2017-0008.html
2017-06-08
Published