imPC@ndo IT

Tracker / CVE-2017-4925

CVE-2017-4925

Medium 5.5

VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Affected products and versions

vmware esxi
vmware fusion · 8.0.0 → 8.5.4
vmware workstation · 12.0.0 → 12.5.3
vmware workstation_pro · 12.0.0 → 12.5.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References