CVE-2017-4916
published 2017-05-22CVE-2017-4916: VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may…
PriorityP339medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EXPLOIT
EPSS
4.95%
91.2th percentile
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vmware_workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro_player | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation update addresses multiple security issues
vendor_vmware·2017-05-18·CVSS 7.8
CVE-2017-4915 [HIGH] VMware Workstation update addresses multiple security issues
VMSA-2017-0009: VMware Workstation update addresses multiple security issues
a. VMware Workstation Insecure library loading vulnerability VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine. VMware would like to thank Jann Horn of Google Project Zero for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4915 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Repl
GHSA
GHSA-mq2h-65qj-q6wr: VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver
ghsa_unreviewed·2022-05-17
CVE-2017-4916 [MEDIUM] CWE-476 GHSA-mq2h-65qj-q6wr: VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98560http://www.securitytracker.com/id/1038526https://www.exploit-db.com/exploits/42140/https://www.vmware.com/security/advisories/VMSA-2017-0009.htmlhttp://www.securityfocus.com/bid/98560http://www.securitytracker.com/id/1038526https://www.exploit-db.com/exploits/42140/https://www.vmware.com/security/advisories/VMSA-2017-0009.html
2017-05-22
Published