Vulnerability CVE-2017-4950


Published: 2018-01-11

Description:
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.

Type:

CWE-190

(Integer Overflow or Wraparound)

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Vmware -> Fusion 
Vmware -> Workstation 

 References:
http://www.securityfocus.com/bid/102490
http://www.securitytracker.com/id/1040161
https://www.vmware.com/security/advisories/VMSA-2018-0005.html

Copyright 2024, cxsecurity.com

 

Back to Top