Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-4901

EPSS 14.12% · P94
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-4901

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
VMWare Workstation和Fusion 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
VMWare Workstation和Fusion都是美国威睿(VMware)公司的桌面虚拟计算机软件,前者提供可以同时运行多个不同的操作系统的虚拟机功能,后者是用于在苹果机(Mac)上运行Windows应用程序的虚拟机软件。 VMware Workstation 12.5.4之前的12.x版本和Fusion 8.5.5之前的8.x版本中的‘drag-and-drop (DnD)’函数存在越边界内存访问漏洞。攻击者可利用该漏洞在操作系统上执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
VMwareWorkstation Pro/Player 12.x prior to 12.5.4 -
VMwareFusion Pro / Fusion 8.x prior to 8.5.5. -

II. Public POCs for CVE-2017-4901

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-4901

登录查看更多情报信息。

Same Patch Batch · VMware · 2017-06-08 · 9 CVEs total

CVE-2017-4918VMware Horizon View Client 命令注入漏洞
CVE-2017-4907VMware Unified Access Gateway和Horizon View 缓冲区错误漏洞
CVE-2017-4908VMware Workstation和Horizon View Client JPEG2000解析器缓冲区错误漏洞
CVE-2017-4909VMware Workstation和Horizon View Client TrueType Font解析器缓冲区错误漏洞
CVE-2017-4910VMware Workstation和Horizon View Client JPEG2000解析器安全漏洞
CVE-2017-4911VMware Workstation和Horizon View Client JPEG2000解析器安全漏洞
CVE-2017-4912VMware Workstation和Horizon View Client TrueType Font解析器安全漏洞
CVE-2017-4913VMWare Workstation和Horizon View Client 数字错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-4901

No comments yet


Leave a comment