CVE Vulnerabilities

CVE-2017-4938

NULL Pointer Dereference

Published: Nov 17, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
WorkstationVmware12.0.0 (including)12.0.0 (including)
WorkstationVmware12.0.1 (including)12.0.1 (including)
WorkstationVmware12.1 (including)12.1 (including)
WorkstationVmware12.1.1 (including)12.1.1 (including)
WorkstationVmware12.5 (including)12.5 (including)
WorkstationVmware12.5.1 (including)12.5.1 (including)
WorkstationVmware12.5.2 (including)12.5.2 (including)
WorkstationVmware12.5.3 (including)12.5.3 (including)
WorkstationVmware12.5.4 (including)12.5.4 (including)
WorkstationVmware12.5.5 (including)12.5.5 (including)
WorkstationVmware12.5.6 (including)12.5.6 (including)
WorkstationVmware12.5.7 (including)12.5.7 (including)

Potential Mitigations

References