2.1
CVSSv2

CVE-2017-4905

Published: 07/06/2017 Updated: 07/02/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x before 12.5.5; and Fusion Pro / Fusion 8.x before 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware fusion

vmware fusion pro

vmware esxi 6.0

vmware esxi 6.5

vmware esxi 5.5

vmware workstation player

vmware workstation pro

Exploits

# VMware Escape Exploit VMware Escape Exploit before VMware WorkStation 1253 Host Target: Win10 x64 Compiler: VS2013 Test on VMware 1252 build-4638234 # Known issues * Failing to heap manipulation causes host process crash (About 50% successful rate ) * Not quite elaborate because I'm not good at doing heap "fengshui" on winows LFH # ...