← Back

CVE-2017-4941

nvd nist
Published: Dec 20, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC session. Note: In order for exploitation to be possible in ESXi, VNC must be manually enabled in a virtual machine's .vmx configuration file. In addition, ESXi must be configured to allow VNC traffic through the built-in firewall.

Affected (88)

3 products
Fusion
Workstation
Esxi
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 8.0.0 to 8.5.9
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 12.0.0 to 12.5.8
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 5.5
Version 5.5 550-20170901001s
Version 5.5 550-20170904001
Configuration D
83 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 6.0
Version 6.0 1
Version 6.0 1a
Version 6.0 1b
Version 6.0 2
Version 6.0 3
Version 6.0 3a
Version 6.0 600-201504401
Version 6.0 600-201505401
Version 6.0 600-201507101
Version 6.0 600-201507102
Version 6.0 600-201507401
Version 6.0 600-201507402
Version 6.0 600-201507403
Version 6.0 600-201507404
Version 6.0 600-201507405
Version 6.0 600-201507406
Version 6.0 600-201507407
Version 6.0 600-201509101
Version 6.0 600-201509102
Version 6.0 600-201509201
Version 6.0 600-201509202
Version 6.0 600-201509203
Version 6.0 600-201509204
Version 6.0 600-201509205
Version 6.0 600-201509206
Version 6.0 600-201509207
Version 6.0 600-201509208
Version 6.0 600-201509209
Version 6.0 600-201509210
Version 6.0 600-201510401
Version 6.0 600-201511401
Version 6.0 600-201601101
Version 6.0 600-201601102
Version 6.0 600-201601401
Version 6.0 600-201601402
Version 6.0 600-201601403
Version 6.0 600-201601404
Version 6.0 600-201601405
Version 6.0 600-201602401
Version 6.0 600-201603101
Version 6.0 600-201603102
Version 6.0 600-201603201
Version 6.0 600-201603202
Version 6.0 600-201603203
Version 6.0 600-201603204
Version 6.0 600-201603205
Version 6.0 600-201603206
Version 6.0 600-201603207
Version 6.0 600-201603208
Version 6.0 600-201605401
Version 6.0 600-201608101
Version 6.0 600-201608401
Version 6.0 600-201608402
Version 6.0 600-201608403
Version 6.0 600-201608404
Version 6.0 600-201608405
Version 6.0 600-201610410
Version 6.0 600-201611401
Version 6.0 600-201611402
Version 6.0 600-201611403
Version 6.0 600-201702101
Version 6.0 600-201702102
Version 6.0 600-201702201
Version 6.0 600-201702202
Version 6.0 600-201702203
Version 6.0 600-201702204
Version 6.0 600-201702205
Version 6.0 600-201702206
Version 6.0 600-201702207
Version 6.0 600-201702208
Version 6.0 600-201702209
Version 6.0 600-201702210
Version 6.0 600-201702211
Version 6.0 600-201702212
Version 6.0 600-201703401
Version 6.0 600-201706101
Version 6.0 600-201706102
Version 6.0 600-201706103
Version 6.0 600-201706401
Version 6.0 600-201706402
Version 6.0 600-201706403
Version 6.0 600-201710301

References (6)

Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.