CVE Database
/

CVE-2017-4950

Back to search

CVE-2017-4950

Published: Jan 11, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.

VendorProductVersions

VMware

Workstation Pro / Player

affected
14.x before 14.1.1
affected
12.x before 12.5.9

VMware

Fusion

affected
10.x before 10.1.1
affected
8.x before 8.5.10

References

1040161
vdb-entry
x_refsource_SECTRACK
102490
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now