CVE-2017-4950: VMware Fusion

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.

Affected products

  • VMware Fusion: from 8.0, before 8.5.10 (fixed in 8.5.10); from 10.0, before 10.1.1 (fixed in 10.1.1)
  • VMware Workstation: from 12.0, before 12.5.9 (fixed in 12.5.9); from 14.0, before 14.1.1 (fixed in 14.1.1)

Published 2018-01-11. Last modified 2026-06-17.