« Volver al listado

CVE-2017-4899

Estado: ModificadaMedia (4.7)—

VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-4899",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "VMware",
          "product": "Workstation Pro/Player",
          "versions": [
            {
              "status": "affected",
              "version": "12.x prior to version 12.5.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-07T18:29:00.257",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/96771",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1037979",
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2017-0003.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/96771",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1037979",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2017-0003.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed."
    },
    {
      "lang": "es",
      "value": "Workstation Pro/Player versiones 12.x anteriores a 12.5.3 de VMware, contiene una vulnerabilidad de seguridad que se presenta en el controlador SVGA. Un atacante puede explotar este problema para bloquear la máquina virtual o activar una lectura fuera de límite. Nota: este problema se puede desencadenar solo cuando el host no tiene tarjeta gráfica o no hay controladores gráficos instalados."
    }
  ],
  "lastModified": "2026-06-17T01:19:31.353",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:workstation_player:12.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ABE47D4-506C-4132-829B-19A61ED35F4A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_player:12.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67CDB0AC-25B6-4397-9784-386C81C37352"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_player:12.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C48608C8-B7A6-47DD-8C78-44EB2B0D6C0C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_player:12.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E1D4E53-DEB3-4143-B619-4431DB47341F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_player:12.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C83B3D50-43FF-4034-9C75-F44939D60378"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_pro:12.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3E8337D-BC36-4910-A998-309D277D008C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_pro:12.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E91FE31-B442-4EE3-A415-D635A5CCA6C2"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_pro:12.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C67B92FB-CE89-479D-97DF-237C77BF307B"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_pro:12.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8A83855-1411-4CA8-A005-5AA58D1CB32A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation_pro:12.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3516D484-83AF-470E-9E9A-AFE3BBE4F75D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}