CVE-2017-4915: VMware Workstation Player

High severity, CVSS 7.8. EPSS: 5.4% chance of exploitation in the next 30 days.

VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.

Affected products

  • VMware Workstation Player: version 12.0.0 only
  • VMware Workstation Pro: version 12.0.0 only

Published 2017-05-22. Last modified 2026-06-17.