Back
CVE-2017-4901
CRITICAL
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Published: Jun 8, 2017
Modified: Jun 17, 2026
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products (18)
| Vendor | Product | Version |
|---|---|---|
| vmware | fusion | 8.0.0 |
| vmware | fusion | 8.0.1 |
| vmware | fusion | 8.0.2 |
| vmware | fusion | 8.1.0 |
| vmware | fusion | 8.1.1 |
| vmware | fusion | 8.5.0 |
| vmware | fusion | 8.5.1 |
| vmware | fusion | 8.5.2 |
| vmware | fusion | 8.5.3 |
| vmware | fusion | 8.5.4 |
| vmware | workstation | 12.0 |
| vmware | workstation | 12.0.1 |
| vmware | workstation | 12.1 |
| vmware | workstation | 12.1.1 |
| vmware | workstation | 12.5 |
| vmware | workstation | 12.5.1 |
| vmware | workstation | 12.5.2 |
| vmware | workstation | 12.5.3 |
GitHub Security Advisory GHSA-8xg8-8x73-gmmx
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x...
References (6)
- http://www.securityfocus.com/bid/96881 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038025
- https://www.vmware.com/security/advisories/VMSA-2017-0005.html Vendor Advisory
- http://www.securityfocus.com/bid/96881 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038025
- https://www.vmware.com/security/advisories/VMSA-2017-0005.html Vendor Advisory
Risk Scores
CVSS Score
9.9 / 10
EPSS Score
19.94%
Top 3% most likely to be exploited
Threat Score
45.6 / 100
Data Sources
NVD
EPSS
GitHub