PT-2017-2233 · Vmware · Vmware Workstation Player+4

Published

2017-03-30

·

Updated

2022-02-07

·

CVE-2017-4904

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware ESXi versions 5.5 without patch ESXi550-201703401-SG VMware ESXi versions 6.0 U1 without patch ESXi600-201703402-SG VMware ESXi versions 6.0 U2 without patch ESXi600-201703403-SG VMware ESXi versions 6.0 U3 without patch ESXi600-201703401-SG VMware ESXi versions 6.5 without patch ESXi650-201703410-SG VMware Workstation Pro / Player versions prior to 12.5.5 VMware Fusion Pro / Fusion versions prior to 8.5.6
Description The issue is related to the XHCI controller in VMware products, which has uninitialized memory usage. This may allow a guest to execute code on the host, potentially leading to privilege escalation. On ESXi 5.5, the issue is reduced to a Denial of Service of the guest.
Recommendations For VMware ESXi 5.5, apply patch ESXi550-201703401-SG to resolve the issue. For VMware ESXi 6.0 U1, apply patch ESXi600-201703402-SG to resolve the issue. For VMware ESXi 6.0 U2, apply patch ESXi600-201703403-SG to resolve the issue. For VMware ESXi 6.0 U3, apply patch ESXi600-201703401-SG to resolve the issue. For VMware ESXi 6.5, apply patch ESXi650-201703410-SG to resolve the issue. For VMware Workstation Pro / Player, update to version 12.5.5 or later to resolve the issue. For VMware Fusion Pro / Fusion, update to version 8.5.6 or later to resolve the issue.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01427
CVE-2017-4904
ZDI-17-239

Affected Products

Vmware Esxi
Vmware Fusion
Vmware Fusion Pro
Vmware Workstation
Vmware Workstation Player