CVE-2017-4941

Published: Dic 20, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2017-14058 Aliases: GSD-2017-4941
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
MEDIUM 6,0
Access Vector: network
Access Complexity: medium
Authentication: single
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC session. Note: In order for exploitation to be possible in ESXi, VNC must be manually enabled in a virtual machine's .vmx configuration file. In addition, ESXi must be configured to allow VNC traffic through the built-in firewall.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0478
Percentile
0,9th
Updated

EPSS Score Trend (Last 90 Days)

119

Improper Restriction of Operations within the Bounds of a Memory Buffer

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Memory Read Memory Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory)
Applicable Platforms
Languages: Assembly, C, C++, Memory-Unsafe
View CWE Details
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201710301:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201706402:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509208:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201602401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201608403:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603205:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509203:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507404:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601404:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702203:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Workstation by Vmware

Version Range Affected
From 12.0.0 (inclusive)
To 12.5.8 (exclusive)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509204:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509202:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601403:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201605401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201706403:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509201:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Fusion by Vmware

Version Range Affected
From 8.0.0 (inclusive)
To 8.5.9 (exclusive)
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509209:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509205:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201504401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603206:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201510401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702208:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201706401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:1b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601402:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201608401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702207:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:5.5:550-20170901001s:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507405:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201511401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:5.5:550-20170904001:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509210:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601405:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603208:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702212:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507406:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201505401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702206:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201611402:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201608404:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201611403:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201608405:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702201:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201703401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201610410:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702210:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702209:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603207:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201706102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201706103:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603203:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509207:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509206:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:5.5:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702211:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201608101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:3a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507402:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603201:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201611401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201706101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507403:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201509101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702205:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201601401:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201507407:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702204:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603202:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201608402:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201603204:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:1a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Esxi by Vmware

cpe:2.3:o:vmware:esxi:6.0:600-201702202:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.vmware.com/security/advisories/VMSA-2017-0021.html
http://www.securitytracker.com/id/1040024
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040024
http://www.securitytracker.com/id/1040025
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040025
https://www.vmware.com/security/advisories/VMSA-2017-0021.html
http://www.securitytracker.com/id/1040024
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040024
http://www.securitytracker.com/id/1040025
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040025