CVE Vulnerabilities

CVE-2017-4938

NULL Pointer Dereference

Published: Nov 17, 2017 | Modified: Dec 04, 2017
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Workstation Vmware 12.0.0 (including) 12.0.0 (including)
Workstation Vmware 12.0.1 (including) 12.0.1 (including)
Workstation Vmware 12.1 (including) 12.1 (including)
Workstation Vmware 12.1.1 (including) 12.1.1 (including)
Workstation Vmware 12.5 (including) 12.5 (including)
Workstation Vmware 12.5.1 (including) 12.5.1 (including)
Workstation Vmware 12.5.2 (including) 12.5.2 (including)
Workstation Vmware 12.5.3 (including) 12.5.3 (including)
Workstation Vmware 12.5.4 (including) 12.5.4 (including)
Workstation Vmware 12.5.5 (including) 12.5.5 (including)
Workstation Vmware 12.5.6 (including) 12.5.6 (including)
Workstation Vmware 12.5.7 (including) 12.5.7 (including)

Potential Mitigations

References