CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-4907 VMware Workstation Pro and Player Multiple Vulnerabilities.(VMSA-2017-0008)

2017年4月21日 1651点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

VMware Workstation is a hosted hypervisor that runs on x64 versions of Windows and Linux operating systems.

VMware Workstation update addresses multiple security issues
A local user on the guest system can create a specially crafted JPEG2000 [CVE-2017-4908] or TrueType Font [CVE-2017-4909] file that, when printed, will trigger a heap overflow in Cortado ThinPrint (TPView.dll) and cause denial of service conditions or execute arbitrary code on the host Windows operating system that is running Workstation.
A local user on the guest system can create a specially crafted JPEG2000 [CVE-2017-4910, CVE-2017-4911] or TrueType Font [CVE-2017-4912] file that, when printed, will trigger an out-of-bounds memory access error in Cortado ThinPrint (TPView.dll) and cause denial of service conditions or execute arbitrary code on the host Windows operating system that is running Workstation.

漏洞危害

A local user on the guest system can cause denial of service conditions on the host system.
A local user on the guest system can gain elevated privileges on the host system.

解决方案

The vendor has issued a fix (12.5.3). For more details refer this advisory VMSA-2017-0008

Patch:
Following are links for downloading patches to fix the vulnerabilities:

VMSA-2017-0008: Windows

0day

标签: 暂无
最后更新:2017年4月21日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me