KLA11175
DoS and ACE vulnerabilities in VMware Products
Updated: 07/05/2018
CVSS
?
6.5
Detect date
?
01/04/2018
Severity
?
High
Description

Multiple serious vulnerabilities have been found in VMware Products. Malicious users can exploit these vulnerabilities to cause denial of service and execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An out-of-bounds read vulnerability in TPView.dll can be exploited remotely to cause denial of service;
  2. A guest access control vulnerability in VMware Tools can be exploited remotely to execute arbitrary code.
Affected products

VMware Horizon View Client for Windows earlier than 4.7.0
VMware Workstation earlier than 14.1.0
VMware Tools earlier than 10.2.0

Solution

Update to latest versions
Download VMware Fusion
Download VMware Workstation Pro

Original advisories

VMSA-2018-0003

Impacts
?
ACE 
[?]

DoS 
[?]
Related products
VMware Workstation
VMware Horizon View Client
VMware Fusion
CVE-IDS
?

CVE-2017-4948
CVE-2017-4945