Lucene search

K
cveVmwareCVE-2017-4902
HistoryJun 07, 2017 - 6:29 p.m.

CVE-2017-4902

2017-06-0718:29:00
CWE-119
vmware
web.nvd.nist.gov
74
vmware
esxi
workstation
player
fusion
heap buffer overflow
svga
code execution
nvd
cve-2017-4902

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

48.1%

VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.

Affected configurations

Nvd
Node
vmwareworkstation_playerRange12.0.012.5.5
OR
vmwareworkstation_proRange12.0.012.5.5
OR
vmwareesxiMatch5.5-
OR
vmwareesxiMatch5.51
OR
vmwareesxiMatch5.52
OR
vmwareesxiMatch5.53a
OR
vmwareesxiMatch5.53b
OR
vmwareesxiMatch6.5-
OR
vmwareesxiMatch6.5650-201701001
OR
vmwareesxiMatch6.5650-201703001
OR
vmwareesxiMatch6.5650-201703002
Node
applemac_os_xMatch-
AND
vmwarefusionRange8.0.08.5.6
OR
vmwarefusion_proRange8.0.08.5.6
VendorProductVersionCPE
vmwareworkstation_player*cpe:2.3:a:vmware:workstation_player:*:*:*:*:*:*:*:*
vmwareworkstation_pro*cpe:2.3:a:vmware:workstation_pro:*:*:*:*:*:*:*:*
vmwareesxi5.5cpe:2.3:o:vmware:esxi:5.5:-:*:*:*:*:*:*
vmwareesxi5.5cpe:2.3:o:vmware:esxi:5.5:1:*:*:*:*:*:*
vmwareesxi5.5cpe:2.3:o:vmware:esxi:5.5:2:*:*:*:*:*:*
vmwareesxi5.5cpe:2.3:o:vmware:esxi:5.5:3a:*:*:*:*:*:*
vmwareesxi5.5cpe:2.3:o:vmware:esxi:5.5:3b:*:*:*:*:*:*
vmwareesxi6.5cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:*
vmwareesxi6.5cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:*
vmwareesxi6.5cpe:2.3:o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:*
Rows per page:
1-10 of 141

CNA Affected

[
  {
    "product": "ESXi",
    "vendor": "VMware",
    "versions": [
      {
        "status": "affected",
        "version": "6.5 without patch ESXi650-201703410-SG"
      },
      {
        "status": "affected",
        "version": "5.5 without patch ESXi550-201703401-SG"
      }
    ]
  },
  {
    "product": "Workstation Pro / Player",
    "vendor": "VMware",
    "versions": [
      {
        "status": "affected",
        "version": "12.x prior to 12.5.5"
      }
    ]
  },
  {
    "product": "Fusion Pro / Fusion",
    "vendor": "VMware",
    "versions": [
      {
        "status": "affected",
        "version": "8.x prior to 8.5.6"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

48.1%