← Back

CVE-2017-4898

nvd nist
Published: Jun 7, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.

Affected (12)

2 products
Workstation Player
Workstation Pro
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 12.0.0
Version 12.0.1
Version 12.1.0
Version 12.5.0
Version 12.5.1
Version 12.5.2
Vmware
Version 12.0.0
Version 12.0.1
Version 12.1.0
Version 12.5.0
Version 12.5.1
Version 12.5.2

References (6)

Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.