CVE-2017-4949: VMware Fusion

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.

Affected products

  • VMware Fusion: from 8.0, before 8.5.10 (fixed in 8.5.10); from 10.0, before 10.1.1 (fixed in 10.1.1)
  • VMware Workstation: from 12.0, before 12.5.9 (fixed in 12.5.9); from 14.0, before 14.1.1 (fixed in 14.1.1)

Published 2018-01-11. Last modified 2026-06-17.