CVE-2017-4938

EUVD-2017-14055
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
vmwareworkstation
12.0.0
vmwareworkstation
12.0.1
vmwareworkstation
12.1
vmwareworkstation
12.1.1
vmwareworkstation
12.5
vmwareworkstation
12.5.1
vmwareworkstation
12.5.2
vmwareworkstation
12.5.3
vmwareworkstation
12.5.4
vmwareworkstation
12.5.5
vmwareworkstation
12.5.6
vmwareworkstation
12.5.7
vmwarefusion
8.0.0
vmwarefusion
8.0.1
vmwarefusion
8.0.2
vmwarefusion
8.1.0
vmwarefusion
8.1.1
vmwarefusion
8.5.0
vmwarefusion
8.5.1
vmwarefusion
8.5.2
vmwarefusion
8.5.3
vmwarefusion
8.5.4
vmwarefusion
8.5.5
vmwarefusion
8.5.6
vmwarefusion
8.5.7
vmwarefusion
8.5.8
𝑥
= Vulnerable software versions