CVE-2017-4937
published 2017-11-17CVE-2017-4937: VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser…
PriorityP336high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
0.39%
31.6th percentile
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View Client.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion_pro | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view | — | — |
| vmware | horizon_view_client_for_windows | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_horizon | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation, Fusion and Horizon View Client updates resolve multiple security vulnerabilities
vendor_vmware·2017-11-16·CVSS 8.8
CVE-2017-4934 [HIGH] VMware Workstation, Fusion and Horizon View Client updates resolve multiple security vulnerabilities
VMSA-2017-0018: VMware Workstation, Fusion and Horizon View Client updates resolve multiple security vulnerabilities
VMware Workstation, Fusion and Horizon View Client updates resolve multiple security vulnerabilities 2. Relevant Products VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion)3. Problem Description a. Heap buffer-overflow vulnerability in VMNAT device VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host. VMware would like to thank Jun Mao of Tencent PC Manager working with Trend Micro's Zero Day Initiative for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4934 to this i
GHSA
GHSA-fvrv-wxg5-6w3x: VMware Workstation (12
ghsa_unreviewed·2022-05-17
CVE-2017-4937 [HIGH] CWE-125 GHSA-fvrv-wxg5-6w3x: VMware Workstation (12
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View Client.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101892http://www.securitytracker.com/id/1039835http://www.securitytracker.com/id/1039836https://www.vmware.com/security/advisories/VMSA-2017-0018.htmlhttp://www.securityfocus.com/bid/101892http://www.securitytracker.com/id/1039835http://www.securitytracker.com/id/1039836https://www.vmware.com/security/advisories/VMSA-2017-0018.html
2017-11-17
Published