Vulnerability record · CVE-2017-4901 · published 8 June 2017
CVE-2017-4901: Vmware fusion memory buffer overflow vulnerability
Vmware · Fusion
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Description
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96881 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038025 | |
| https://www.vmware.com/security/advisories/VMSA-2017-0005.html | Vendor Advisory |
| http://www.securityfocus.com/bid/96881 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038025 | |
| https://www.vmware.com/security/advisories/VMSA-2017-0005.html | Vendor Advisory |
Track CVE-2017-4901 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-4901), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.