5.5

CVE-2017-4925

VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Data is provided by the National Vulnerability Database (NVD)
VMwareESXi Version5.5 Update-
VMwareESXi Version5.5 Update1
VMwareESXi Version5.5 Update2
VMwareESXi Version5.5 Update3a
VMwareESXi Version5.5 Update3b
VMwareESXi Version5.5 Update550-20170901001s
VMwareESXi Version6.0 Update-
VMwareESXi Version6.0 Update1
VMwareESXi Version6.0 Update1a
VMwareESXi Version6.0 Update1b
VMwareESXi Version6.0 Update2
VMwareESXi Version6.0 Update3
VMwareESXi Version6.0 Update3a
VMwareESXi Version6.0 Update600-201504401
VMwareESXi Version6.0 Update600-201505401
VMwareESXi Version6.0 Update600-201507101
VMwareESXi Version6.0 Update600-201507102
VMwareESXi Version6.0 Update600-201507401
VMwareESXi Version6.0 Update600-201507402
VMwareESXi Version6.0 Update600-201507403
VMwareESXi Version6.0 Update600-201507404
VMwareESXi Version6.0 Update600-201507405
VMwareESXi Version6.0 Update600-201507406
VMwareESXi Version6.0 Update600-201507407
VMwareESXi Version6.0 Update600-201509101
VMwareESXi Version6.0 Update600-201509102
VMwareESXi Version6.0 Update600-201509201
VMwareESXi Version6.0 Update600-201509202
VMwareESXi Version6.0 Update600-201509203
VMwareESXi Version6.0 Update600-201509204
VMwareESXi Version6.0 Update600-201509205
VMwareESXi Version6.0 Update600-201509206
VMwareESXi Version6.0 Update600-201509207
VMwareESXi Version6.0 Update600-201509208
VMwareESXi Version6.0 Update600-201509209
VMwareESXi Version6.0 Update600-201509210
VMwareESXi Version6.0 Update600-201510401
VMwareESXi Version6.0 Update600-201511401
VMwareESXi Version6.0 Update600-201601101
VMwareESXi Version6.0 Update600-201601102
VMwareESXi Version6.0 Update600-201601401
VMwareESXi Version6.0 Update600-201601402
VMwareESXi Version6.0 Update600-201601403
VMwareESXi Version6.0 Update600-201601404
VMwareESXi Version6.0 Update600-201601405
VMwareESXi Version6.0 Update600-201602401
VMwareESXi Version6.0 Update600-201603101
VMwareESXi Version6.0 Update600-201603102
VMwareESXi Version6.0 Update600-201603201
VMwareESXi Version6.0 Update600-201603202
VMwareESXi Version6.0 Update600-201603203
VMwareESXi Version6.0 Update600-201603204
VMwareESXi Version6.0 Update600-201603205
VMwareESXi Version6.0 Update600-201603206
VMwareESXi Version6.0 Update600-201603207
VMwareESXi Version6.0 Update600-201603208
VMwareESXi Version6.0 Update600-201605401
VMwareESXi Version6.0 Update600-201608101
VMwareESXi Version6.0 Update600-201608401
VMwareESXi Version6.0 Update600-201608402
VMwareESXi Version6.0 Update600-201608403
VMwareESXi Version6.0 Update600-201608404
VMwareESXi Version6.0 Update600-201608405
VMwareESXi Version6.0 Update600-201610410
VMwareESXi Version6.0 Update600-201611401
VMwareESXi Version6.0 Update600-201611402
VMwareESXi Version6.0 Update600-201611403
VMwareESXi Version6.0 Update600-201702101
VMwareESXi Version6.0 Update600-201702102
VMwareESXi Version6.0 Update600-201702201
VMwareESXi Version6.0 Update600-201702202
VMwareESXi Version6.0 Update600-201702203
VMwareESXi Version6.0 Update600-201702204
VMwareESXi Version6.0 Update600-201702205
VMwareESXi Version6.0 Update600-201702206
VMwareESXi Version6.0 Update600-201702207
VMwareESXi Version6.0 Update600-201702208
VMwareESXi Version6.0 Update600-201702209
VMwareESXi Version6.0 Update600-201702210
VMwareESXi Version6.0 Update600-201702211
VMwareESXi Version6.0 Update600-201702212
VMwareESXi Version6.0 Update600-201703401
VMwareESXi Version6.5 Update-
VMwareESXi Version6.5 Update650-201701001
VMwareESXi Version6.5 Update650-201703001
VMwareESXi Version6.5 Update650-201703002
VMwareESXi Version6.5 Update650-201704001
VMwareWorkstation Version >= 12.0.0 < 12.5.3
VMwareWorkstation Pro Version >= 12.0.0 < 12.5.3
VMwareFusion Version >= 8.0.0 < 8.5.4
   ApplemacOS X Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.412
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.