« Volver al listado

CVE-2017-4939

Estado: ModificadaAlta (7.8)—

El instalador de VMware Workstation (en versiones 12.x anteriores a la 12.5.8) contiene un error de secuestro de DLL que existe debido a que la aplicación carga algunos archivos DLL de manera incorrecta. Este error puede permitir que un atacante cargue un archivo DLL elegido por él que podría ejecutar código arbitrario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-4939",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "VMware",
          "product": "Workstation",
          "versions": [
            {
              "status": "affected",
              "version": "12.x before 12.5.8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-17T21:29:00.417",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/101890",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2017-0018.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/101890",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2017-0018.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-426"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "El instalador de VMware Workstation (en versiones 12.x anteriores a la 12.5.8) contiene un error de secuestro de DLL que existe debido a que la aplicación carga algunos archivos DLL de manera incorrecta. Este error puede permitir que un atacante cargue un archivo DLL elegido por él que podría ejecutar código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T01:19:36.327",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C4C2CB0-9A2B-46B2-9E75-2BADAE722BB0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D38FB28D-8A42-4877-92AF-39EE04B14DB1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66C64A90-90A2-450A-8A79-AB69B5A939DC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42EF613B-3436-4951-8F4D-9F22144E06CA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E293B67-98C3-4D8E-883C-2F2F774AE6F0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB307F39-3A90-4B62-B2BF-0E0CEBBBBC9F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "838C7C08-15ED-4379-8A5B-9419D13AE7FF"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C064187-0870-4672-9D64-92D643FA9C86"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60F08698-0194-4892-9A46-93C53C0C660B"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "287275D4-E311-4A1B-BC5C-2FB3A64691E0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:12.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED552760-4DB1-4E56-B6C1-23E053858055"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}