CVE-2017-4901
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
08/06/2017
Last modified:
20/04/2025
Description
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:fusion:8.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.5.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.5.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.5.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:fusion:8.5.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workstation:12.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workstation:12.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workstation:12.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workstation:12.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workstation:12.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page