CVE Vulnerabilities

CVE-2017-4898

Published: Jun 07, 2017 | Modified: Oct 03, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the vmware-vmx process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.

Affected Software

Name Vendor Start Version End Version
Workstation_player Vmware 12.0.0 (including) 12.0.0 (including)
Workstation_player Vmware 12.0.1 (including) 12.0.1 (including)
Workstation_player Vmware 12.1.0 (including) 12.1.0 (including)
Workstation_player Vmware 12.5.0 (including) 12.5.0 (including)
Workstation_player Vmware 12.5.1 (including) 12.5.1 (including)
Workstation_player Vmware 12.5.2 (including) 12.5.2 (including)
Workstation_pro Vmware 12.0.0 (including) 12.0.0 (including)
Workstation_pro Vmware 12.0.1 (including) 12.0.1 (including)
Workstation_pro Vmware 12.1.0 (including) 12.1.0 (including)
Workstation_pro Vmware 12.5.0 (including) 12.5.0 (including)
Workstation_pro Vmware 12.5.1 (including) 12.5.1 (including)
Workstation_pro Vmware 12.5.2 (including) 12.5.2 (including)

References