CVE-2017-4898
HIGH 8.8EPSS 0.4%
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 0.39% chance of exploitation in the next 30 days, 32th percentile
- Published
- 2017-06-07
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- ivildeed/vmw_vmx_overloader141★ · 2017-04-04