CVE-2017-4916: VMware Workstation Player

Medium severity, CVSS 6.5. EPSS: 5% chance of exploitation in the next 30 days.

VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.

Affected products

  • VMware Workstation Player: version 12.0.0 only
  • VMware Workstation Pro: version 12.0.0 only

Published 2017-05-22. Last modified 2026-06-17.