Vulnerability in XHCI Controller of VMware ESXi and Workstation
CVE-2017-4904
8.8HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 7 June 2017
Summary
The XHCI controller vulnerability in VMware ESXi and Workstation Pro can lead to uninitialized memory usage, potentially allowing unauthorized code execution from a guest virtual machine to the host system. This flaw affects multiple versions of ESXi and Workstation, emphasizing the need for timely updates and patches to mitigate risks. Environments running unsupported or outdated versions may experience denial of service, affecting the stability and security of deployed virtual machines.
Affected Version(s)
ESXi 6.5 without patch ESXi650-201703410-SG
ESXi 6.0 U3 without patch ESXi600-201703401-SG
ESXi 6.0 U2 without patch ESXi600-201703403-SG
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved