4.7

CVE-2017-4899

VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.

Data is provided by the National Vulnerability Database (NVD)
VMwareWorkstation Player Version12.0.0
VMwareWorkstation Player Version12.0.1
VMwareWorkstation Player Version12.1.0
VMwareWorkstation Player Version12.5.0
VMwareWorkstation Player Version12.5.1
VMwareWorkstation Pro Version12.0.0
VMwareWorkstation Pro Version12.0.1
VMwareWorkstation Pro Version12.1.0
VMwareWorkstation Pro Version12.5.0
VMwareWorkstation Pro Version12.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.118
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.7 1 3.6
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:N/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.