KLA11177
Multiple vulnerabilities in VMware products
Updated: 01/15/2018
CVSS
?
7.5
Detect date
?
01/10/2018
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in VMware Workstation and VMware Fusion. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled can be exploited remotely to execute arbitrary code;
  2. An integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled can be exploited remotely to execute arbitrary code;
Affected products

Workstation 14.x earlier than 14.1.1
Workstation 12.x earlier than 12.5.9
Fusion 10.x earlier than 10.1.1
Fusion 8.x earlier than 8.5.10

Solution

Update to latest version
Download VMware Workstation Pro
Download VMware Fusion

Original advisories

VMSA-2018-0005

Impacts
?
ACE 
[?]
Related products
VMware Workstation
VMware Fusion
CVE-IDS
?

CVE-2017-4950
CVE-2017-4949