CVE-2017-4901

critical
Published 2017-06-08 · Modified 2026-05-13
CVSS v3
9.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.9

Description

The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.

Predictions

Exploit likelihood
98%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@vmware.com — https://www.vmware.com/security/advisories/VMSA-2017-0005.html

Application impact

VendorProductVersionsFixed
vmwarefusion8.0.0
vmwarefusion8.0.1
vmwarefusion8.0.2
vmwarefusion8.1.0
vmwarefusion8.1.1
vmwarefusion8.5.0
vmwarefusion8.5.1
vmwarefusion8.5.2
vmwarefusion8.5.3
vmwarefusion8.5.4
vmwareworkstation12.0
vmwareworkstation12.0.1
vmwareworkstation12.1
vmwareworkstation12.1.1
vmwareworkstation12.5
vmwareworkstation12.5.1
vmwareworkstation12.5.2
vmwareworkstation12.5.3

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.