← Vulnerability feed

Vulnerability record · CVE-2017-4915 · published 22 May 2017

CVE-2017-4915: Vmware workstation player incorrect authorization vulnerability

Vmware · Workstation Player

VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.

7.8 CVSS 3.0 High EPSS 5.4% · top 7.6% CWE-863 · Incorrect authorization
7.8CVSS 3.0 base score, v2 7.2
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-4915 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-4933Vmware workstation pro out-of-bounds write vulnerabilityVMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could all…EPSS 3.6%8.8CVE-2017-4924Vmware fusion out-of-bounds write vulnerabilityVMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds wr…EPSS 0.61%8.8CVE-2017-4898Vmware workstation player vulnerabilityVMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a…EPSS 0.39%8.8CVE-2017-4902Vmware workstation player memory buffer overflow vulnerabilityVMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fus…EPSS 0.52%8.8CVE-2017-4903Vmware workstation player memory buffer overflow vulnerabilityVMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with…EPSS 0.41%8.8CVE-2017-4904Vmware fusion memory buffer overflow vulnerabilityThe XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-20…EPSS 0.43%8.8CVE-2016-7461Vmware fusion memory buffer overflow vulnerabilityThe drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion …EPSS 0.54%7.8CVE-2016-7081Vmware workstation player memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when C…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2017-4915), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.