CVE Database
/

CVE-2017-4904

Back to search

CVE-2017-4904

Published: Jun 7, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized memory usage. This issue may allow a guest to execute code on the host. The issue is reduced to a Denial of Service of the guest on ESXi 5.5.

VendorProductVersions

VMware

ESXi

affected
6.5 without patch ESXi650-201703410-SG
affected
6.0 U3 without patch ESXi600-201703401-SG
affected
6.0 U2 without patch ESXi600-201703403-SG
affected
6.0 U1 without patch ESXi600-201703402-SG
affected
5.5 without patch ESXi550-201703401-SG

VMware

Workstation Pro / Player

affected
12.x prior to 12.5.5

VMware

Fusion Pro / Fusion

affected
8.x prior to 8.5.6

References

97165
vdb-entry
x_refsource_BID
1038148
vdb-entry
x_refsource_SECTRACK
1038149
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now