KLA11177
Multiple vulnerabilities in VMware products
Обновлено: 15/01/2018
CVSS
7.5
Дата обнаружения
10/01/2018
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities have been found in VMware Workstation and VMware Fusion. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled can be exploited remotely to execute arbitrary code;
  2. An integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled can be exploited remotely to execute arbitrary code;
Пораженные продукты

Workstation 14.x earlier than 14.1.1
Workstation 12.x earlier than 12.5.9
Fusion 10.x earlier than 10.1.1
Fusion 8.x earlier than 8.5.10

Решение

Update to latest version
Download VMware Workstation Pro
Download VMware Fusion

Первичный источник обнаружения
VMSA-2018-0005
Оказываемое влияние
?
ACE 
[?]
Связанные продукты
VMware Workstation
VMware Fusion
CVE-IDS

CVE-2017-4950
CVE-2017-4949