CVE-2017-4933 is a heap overflow vulnerability affecting VMware ESXi, Workstation, and Fusion, allowing an authenticated VNC session to trigger heap corruption. Successful exploitation could lead to remote code execution within a virtual machine. This vulnerability has a high severity CVSS score of 8.8, indicating a network-based attack with low privileges and no user interaction required, potentially resulting in full compromise of confidentiality, integrity, and availability. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage. There is no evidence of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0, < 12.5.8CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_pro:*:*:*:*:*:*:*:* | ||
14.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_pro:14.0:*:*:*:*:*:*:* | ||
14.1.0CPE matchmatch criteria | cpe:2.3:a:vmware:workstation_pro:14.1.0:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.