Vulnerability Details CVE-2017-4936
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.1%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.9
Products affected by CVE-2017-4936
-
cpe:2.3:a:vmware:horizon_view:4.0.0
-
cpe:2.3:a:vmware:horizon_view:4.0.1
-
cpe:2.3:a:vmware:horizon_view:4.1
-
cpe:2.3:a:vmware:horizon_view:4.2
-
cpe:2.3:a:vmware:horizon_view:4.3
-
cpe:2.3:a:vmware:horizon_view:4.4
-
cpe:2.3:a:vmware:horizon_view:4.5
-
cpe:2.3:a:vmware:horizon_view:4.6
-
cpe:2.3:a:vmware:workstation:12.0.0
-
cpe:2.3:a:vmware:workstation:12.0.1
-
cpe:2.3:a:vmware:workstation:12.1
-
cpe:2.3:a:vmware:workstation:12.1.1
-
cpe:2.3:a:vmware:workstation:12.5
-
cpe:2.3:a:vmware:workstation:12.5.1
-
cpe:2.3:a:vmware:workstation:12.5.2
-
cpe:2.3:a:vmware:workstation:12.5.3
-
cpe:2.3:a:vmware:workstation:12.5.4
-
cpe:2.3:a:vmware:workstation:12.5.5
-
cpe:2.3:a:vmware:workstation:12.5.6
-
cpe:2.3:a:vmware:workstation:12.5.7