← Vulnerability feed

Vulnerability record · CVE-2017-4898 · published 7 June 2017

CVE-2017-4898: Vmware workstation player vulnerability

Vmware · Workstation Player

VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.

8.8 CVSS 3.0 High EPSS 0.39% · top 69.2%
8.8CVSS 3.0 base score, v2 6.9
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-4898 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-4933Vmware workstation pro out-of-bounds write vulnerabilityVMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could all…EPSS 3.6%8.8CVE-2017-4924Vmware fusion out-of-bounds write vulnerabilityVMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds wr…EPSS 0.61%8.8CVE-2017-4902Vmware workstation player memory buffer overflow vulnerabilityVMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fus…EPSS 0.52%8.8CVE-2017-4903Vmware workstation player memory buffer overflow vulnerabilityVMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with…EPSS 0.41%8.8CVE-2017-4904Vmware fusion memory buffer overflow vulnerabilityThe XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-20…EPSS 0.43%8.8CVE-2016-7461Vmware fusion memory buffer overflow vulnerabilityThe drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion …EPSS 0.54%7.8CVE-2017-4915Vmware workstation player incorrect authorization vulnerabilityVMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation o…EPSS 5.4%7.8CVE-2016-7081Vmware workstation player memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when C…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2017-4898), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.