CVE-2017-4904
Published: Jun 7, 2017
Modified: Aug 5, 2024
Description
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized memory usage. This issue may allow a guest to execute code on the host. The issue is reduced to a Denial of Service of the guest on ESXi 5.5.
| Vendor | Product | Versions |
|---|---|---|
VMware | ESXi | affected 6.5 without patch ESXi650-201703410-SGaffected 6.0 U3 without patch ESXi600-201703401-SGaffected 6.0 U2 without patch ESXi600-201703403-SGaffected 6.0 U1 without patch ESXi600-201703402-SGaffected 5.5 without patch ESXi550-201703401-SG |
VMware | Workstation Pro / Player | affected 12.x prior to 12.5.5 |
VMware | Fusion Pro / Fusion | affected 8.x prior to 8.5.6 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now