Use-After-Free Vulnerability in VMware Workstation and Fusion NAT Service
CVE-2017-4949
7HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 11 January 2018
Summary
VMware Workstation and VMware Fusion have a use-after-free vulnerability in the NAT service, specifically when IPv6 mode is enabled. This vulnerability could allow an attacker to execute arbitrary code on the host system from within a vulnerable guest virtual machine. Notably, IPv6 mode for VMNAT is not activated by default, which may reduce the immediate risk for most users. However, organizations using these products should ensure they are aware of this issue and take appropriate measures to mitigate potential risks.
Affected Version(s)
Fusion 10.x before 10.1.1
Fusion 8.x before 8.5.10
Workstation Pro / Player 14.x before 14.1.1
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved