CVE-2017-4949

EUVD-2017-14066
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
vmwarefusion
8.0 ≤
𝑥
< 8.5.10
vmwarefusion
10.0 ≤
𝑥
< 10.1.1
vmwareworkstation
12.0 ≤
𝑥
< 12.5.9
vmwareworkstation
14.0 ≤
𝑥
< 14.1.1
𝑥
= Vulnerable software versions