CVE Database
/

CVE-2017-4949

Back to search

CVE-2017-4949

Published: Jan 11, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.

VendorProductVersions

VMware

Workstation Pro / Player

affected
14.x before 14.1.1
affected
12.x before 12.5.9

VMware

Fusion

affected
10.x before 10.1.1
affected
8.x before 8.5.10

References

1040161
vdb-entry
x_refsource_SECTRACK
102489
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now