CVE-2017-4901

CRITICAL

VMware Workstation/Fusion <12.5.4-8.5.5 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-4901. PoCs published by unamer.

AI-analyzed exploit summary This exploit targets a VMware Escape vulnerability (CVE-2017-4901) affecting VMware Workstation versions before 12.5.5. It manipulates heap memory to escape the virtual machine and execute code on the host system, specifically tested on Windows 10 x64 with VMware 12.5.2.

Description

The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.

Exploits (1)

exploitdb WORKING POC
by unamer · localwindows
https://www.exploit-db.com/exploits/47714

This exploit targets a VMware Escape vulnerability (CVE-2017-4901) affecting VMware Workstation versions before 12.5.5. It manipulates heap memory to escape the virtual machine and execute code on the host system, specifically tested on Windows 10 x64 with VMware 12.5.2.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: VMware Workstation < 12.5.5
No auth needed
Prerequisites: VMware Workstation < 12.5.5 installed on Windows 10 x64 · Access to a guest VM with the exploit compiled and executed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038025
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96881

Scores

CVSS v3 9.9
EPSS 0.1994
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (20)
vmware/fusion 8.0.0
vmware/fusion 8.0.1
vmware/fusion 8.0.2
vmware/fusion 8.1.0
vmware/fusion 8.1.1
vmware/fusion 8.5.0
vmware/fusion 8.5.1
vmware/fusion 8.5.2
vmware/fusion 8.5.3
vmware/fusion 8.5.4
... and 10 more
Published Jun 08, 2017
Tracked Since Feb 18, 2026