cbcvebase.
CVE-2017-4950
published 2018-01-11

CVE-2017-4950: VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound…

PriorityP428high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.38%
30.6th percentile
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.

Affected

15 ranges
VendorProductVersion rangeFixed in
vmwarefusion
vmwarefusion
vmwarefusion>= 10.0 < 10.1.110.1.1
vmwarefusion>= 8.0 < 8.5.108.5.10
vmwarefusion_pro
vmwarehorizon_client
vmwarevmware_fusion
vmwarevmware_horizon
vmwarevmware_workstation
vmwareworkstation>= 12.0 < 12.5.912.5.9
vmwareworkstation>= 14.0 < 14.1.114.1.1
vmwareworkstation_player
vmwareworkstation_pro
vmwareworkstation_pro_player
vmwareworkstation_pro_player

CVSS provenance

nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.