← back
CVE-2017-4901

CVE-2017-4901

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 20%
from disclosure to weapon61 days
Published on NVDJun 8
1st PoC+61d
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.