cbcvebase.
CVE-2017-4938
published 2017-11-17

CVE-2017-4938: VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of…

PriorityP423medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.37%
29.2th percentile
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion
vmwarefusion_pro
vmwarevmware_fusion
vmwarevmware_horizon
vmwarevmware_workstation
vmwareworkstation
vmwareworkstation
vmwareworkstation
vmwareworkstation
vmwareworkstation
vmwareworkstation

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.