CVE-2017-4945
published 2018-01-05CVE-2017-4945: VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.43%
35.6th percentile
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMware Tools 10.2.0 is consumed by Workstation 14.1.0 and Fusion 10.1.0 by default.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion_pro | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_horizon | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
vRealize Operations for Horizon, vRealize Operations for Published Applications, Workstation, Horizon View Client and Tools updates resolve multiple security vulnerabilities
vendor_vmware·2018-01-04·CVSS 7.8
CVE-2017-4945 [HIGH] vRealize Operations for Horizon, vRealize Operations for Published Applications, Workstation, Horizon View Client and Tools updates resolve multiple security vulnerabilities
VMSA-2018-0003: vRealize Operations for Horizon, vRealize Operations for Published Applications, Workstation, Horizon View Client and Tools updates resolve multiple security vulnerabilities
a. V4H and V4PA desktop agent privilege escalation vulnerability The V4H and V4PA desktop agents contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. VMware would like to thank Martin Lemay of GoSecure Inc. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4946 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available
GHSA
GHSA-8xhx-57h6-9j99: VMware Workstation (14
ghsa_unreviewed·2022-05-13·CVSS 5.5
CVE-2017-4945 [MEDIUM] GHSA-8xhx-57h6-9j99: VMware Workstation (14
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMware Tools 10.2.0 is consumed by Workstation 14.1.0 and Fusion 10.1.0 by default.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102441http://www.securitytracker.com/id/1040109http://www.securitytracker.com/id/1040136https://www.vmware.com/us/security/advisories/VMSA-2018-0003.htmlhttp://www.securityfocus.com/bid/102441http://www.securitytracker.com/id/1040109http://www.securitytracker.com/id/1040136https://www.vmware.com/us/security/advisories/VMSA-2018-0003.html
2018-01-05
Published