CVE-2017-4924
published 2017-09-15CVE-2017-4924: VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.61%
45.1th percentile
VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | >= 8.0.0 < 8.5.8 | 8.5.8 |
| vmware | fusion_pro | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| vmware | workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | >= 12.0.0 < 12.5.7 | 12.5.7 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qqqq-ch5x-6hq4: VMware ESXi (ESXi 6
ghsa_unreviewed·2022-05-13
CVE-2017-4924 [HIGH] CWE-787 GHSA-qqqq-ch5x-6hq4: VMware ESXi (ESXi 6
VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
VMware
VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities
vendor_vmware·2017-09-14·CVSS 8.8
CVE-2017-4924 [HIGH] VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities
VMSA-2017-0015: VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities
VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities. 2. Relevant Products VMware ESXi (ESXi) VMware vCenter Server VMware Workstation Pro / Player (Workstation) VMware Fusion Pro, Fusion (Fusion)3. Problem Description a. Out-of-bounds write vulnerability in SVGA VMware ESXi, Workstation and Fusion contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host. VMware would like to thank Nico Golde and Ralf-Philipp Weinmann of Comsecuris UG (haftungsbeschraenkt) working with ZDI for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.o
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/100843http://www.securitytracker.com/id/1039365http://www.securitytracker.com/id/1039366https://0patch.blogspot.com/2017/10/micropatching-hypervisor-with-running.htmlhttps://www.vmware.com/security/advisories/VMSA-2017-0015.htmlhttp://www.securityfocus.com/bid/100843http://www.securitytracker.com/id/1039365http://www.securitytracker.com/id/1039366https://0patch.blogspot.com/2017/10/micropatching-hypervisor-with-running.htmlhttps://www.vmware.com/security/advisories/VMSA-2017-0015.html
2017-09-15
Published