CVE-2017-4933

Description

VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap corruption. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC session. Note: In order for exploitation to be possible in ESXi, VNC must be manually enabled in a virtual machines .vmx configuration file. In addition, ESXi must be configured to allow VNC traffic through the built-in firewall.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
7.078

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.0.0Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.0.1Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.0.2Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.1.0Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.0Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.1Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.2Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.3Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.4Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.5Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.6Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.7Mac
Vulnerabilities CVE-2017-4933,CVE-2017-4941,CVE-2018-6962,CVE-2018-6963 are affected in VMware Fusion for MAC 10.0Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 10.1.0Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 8.5.8Mac
Vulnerabilities CVE-2017-4933,CVE-2017-4941 are affected in VMware Fusion for MAC 10.0Mac
Multiple Vulnerabilities are affected in VMware Fusion for MAC 10.0Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234