CVE-2017-4900

MEDIUM

VMware Workstation Pro/Player <12.5.3 - Use After Free

Title source: llm

Description

VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (13)
vmware/workstation_player
vmware/workstation_player
vmware/workstation_player
vmware/workstation_player
vmware/workstation_player
vmware/workstation_player
vmware/workstation_pro
vmware/workstation_pro
vmware/workstation_pro
vmware/workstation_pro
... and 3 more
Published Jun 07, 2017
Tracked Since Feb 18, 2026