CVE-2017-4901: VMware Fusion
Critical severity, CVSS 9.9. EPSS: 19.9% chance of exploitation in the next 30 days.
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
Affected products
- VMware Fusion: version 8.0.0 only; version 8.0.1 only; version 8.0.2 only; version 8.1.0 only; version 8.1.1 only; version 8.5.0 only; …
- VMware Workstation: version 12.0 only; version 12.0.1 only; version 12.1 only; version 12.1.1 only; version 12.5 only; version 12.5.1 only; …
Published 2017-06-08. Last modified 2026-06-17.