VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability
Published Sep 15, 2017
5.5
MEDIUMCVSS 3.1
EPSS 0.38%
Description
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Affected products
-
Affected
- 5.5 without patch ESXi550-201709101-SG
- 6.0 without patch ESXi600-201706101-SG
- 6.5 without patch ESXi650-201707101-SG
-
Affected
- 8.x before 8.5.4
-
Affected
- 12.x before 12.5.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
Configuration 1
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
Configuration 2
- ≥ 12.0.0 · < 12.5.3
- ≥ 12.0.0 · < 12.5.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- http://www.securityfocus.com/bid/100842 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039367 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039368 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-14042 Advisory
- https://www.vmware.com/security/advisories/VMSA-2017-0015.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/100842 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039367 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039368 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-14042 | Advisory | |
| https://www.vmware.com/security/advisories/VMSA-2017-0015.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data