CVE-2017-4915 is an insecure library loading vulnerability in VMware Workstation Pro/Player on Linux hosts, stemming from ALSA sound driver configuration files. This flaw allows unprivileged host users to escalate their privileges to root on the Linux host machine. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit modules exist in Metasploit and ExploitDB, indicating readily available exploit code and a moderate level of community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_player:12.0.0:*:*:*:*:*:*:* | ||
12.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_pro:12.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.