Vulnerability Details CVE-2017-4925
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.3%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2017-4925
-
cpe:2.3:a:vmware:fusion:8.0.0
-
cpe:2.3:a:vmware:fusion:8.0.1
-
cpe:2.3:a:vmware:fusion:8.0.2
-
cpe:2.3:a:vmware:fusion:8.1
-
cpe:2.3:a:vmware:fusion:8.1.0
-
cpe:2.3:a:vmware:fusion:8.1.1
-
cpe:2.3:a:vmware:fusion:8.1.4
-
cpe:2.3:a:vmware:fusion:8.5
-
cpe:2.3:a:vmware:fusion:8.5.0
-
cpe:2.3:a:vmware:fusion:8.5.1
-
cpe:2.3:a:vmware:fusion:8.5.2
-
cpe:2.3:a:vmware:fusion:8.5.3
-
cpe:2.3:a:vmware:workstation:12.0.0
-
cpe:2.3:a:vmware:workstation:12.0.1
-
cpe:2.3:a:vmware:workstation:12.1
-
cpe:2.3:a:vmware:workstation:12.1.1
-
cpe:2.3:a:vmware:workstation:12.5
-
cpe:2.3:a:vmware:workstation:12.5.0
-
cpe:2.3:a:vmware:workstation:12.5.1
-
cpe:2.3:a:vmware:workstation:12.5.2
-
cpe:2.3:a:vmware:workstation_pro:12.0.0
-
cpe:2.3:a:vmware:workstation_pro:12.0.1
-
cpe:2.3:a:vmware:workstation_pro:12.1
-
cpe:2.3:a:vmware:workstation_pro:12.1.0
-
cpe:2.3:a:vmware:workstation_pro:12.1.1
-
cpe:2.3:a:vmware:workstation_pro:12.1.2
-
cpe:2.3:a:vmware:workstation_pro:12.5
-
cpe:2.3:a:vmware:workstation_pro:12.5.0
-
cpe:2.3:a:vmware:workstation_pro:12.5.1
-
cpe:2.3:a:vmware:workstation_pro:12.5.2
-
cpe:2.3:o:apple:mac_os_x:-
-
cpe:2.3:o:vmware:esxi:5.5
-
cpe:2.3:o:vmware:esxi:6.0
-
cpe:2.3:o:vmware:esxi:6.5