CVE-2017-4925: VMware ESXi
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Affected products
- VMware ESXi: version 5.5 only; version 6.0 only; version 6.5 only
- VMware Fusion: from 8.0.0, before 8.5.4 (fixed in 8.5.4)
- VMware Workstation: from 12.0.0, before 12.5.3 (fixed in 12.5.3)
- VMware Workstation Pro: from 12.0.0, before 12.5.3 (fixed in 12.5.3)
Published 2017-09-15. Last modified 2026-06-17.