CVE-2017-4898
CVE-2017-4898
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
07 Jun 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.
Affected products
VMware · Workstation Pro/PlayerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →