Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-4936

Опубликовано: 17 нояб. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 6.9
EPSS Низкий

Описание

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:workstation:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:12.5.7:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:vmware:horizon_view:4.0.0:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.0.1:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.1:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.2:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.3:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.4:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.5:*:*:*:*:windows:*:*
cpe:2.3:a:vmware:horizon_view:4.6:*:*:*:*:windows:*:*

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client.

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-125