CVE-2017-4925
published 2017-09-15CVE-2017-4925: VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.38%
30.7th percentile
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | >= 8.0.0 < 8.5.4 | 8.5.4 |
| vmware | fusion_pro | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 12.0.0 < 12.5.3 | 12.5.3 |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
| vmware | workstation_pro | >= 12.0.0 < 12.5.3 | 12.5.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vm9p-h4v4-cfq7: VMware ESXi 6
ghsa_unreviewed·2022-05-13
CVE-2017-4925 [MEDIUM] CWE-476 GHSA-vm9p-h4v4-cfq7: VMware ESXi 6
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
VMware
VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities
vendor_vmware·2017-09-14·CVSS 8.8
CVE-2017-4924 [HIGH] VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities
VMSA-2017-0015: VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities
VMware ESXi, vCenter Server, Fusion and Workstation updates resolve multiple security vulnerabilities. 2. Relevant Products VMware ESXi (ESXi) VMware vCenter Server VMware Workstation Pro / Player (Workstation) VMware Fusion Pro, Fusion (Fusion)3. Problem Description a. Out-of-bounds write vulnerability in SVGA VMware ESXi, Workstation and Fusion contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host. VMware would like to thank Nico Golde and Ralf-Philipp Weinmann of Comsecuris UG (haftungsbeschraenkt) working with ZDI for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.o
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/100842http://www.securitytracker.com/id/1039367http://www.securitytracker.com/id/1039368https://www.vmware.com/security/advisories/VMSA-2017-0015.htmlhttp://www.securityfocus.com/bid/100842http://www.securitytracker.com/id/1039367http://www.securitytracker.com/id/1039368https://www.vmware.com/security/advisories/VMSA-2017-0015.html
2017-09-15
Published