CVE-2017-4903 describes an uninitialized stack memory usage vulnerability within the SVGA component of VMware ESXi (multiple versions), Workstation Pro/Player 12.x, and Fusion Pro/Fusion 8.x. This flaw could allow a malicious guest operating system to execute arbitrary code on the underlying host system. With a CVSS score of 8.8 (HIGH), it represents a significant risk, as a low-privileged attacker on the guest OS could achieve complete compromise of the host with low attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability garnered notable community discussion and media coverage at the time of its disclosure, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0, < 12.5.5CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_player:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.5.5CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_pro:*:*:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:5.5:-:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:5.5:1:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:5.5:2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.