CVE-2017-4907
Last modified
CVE-2017-4907 is a vulnerability of currently unknown severity. VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.. EPSS estimates a 3.76% chance of exploitation in the next 30 days.
Description
VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Horizon View | 6.0 |
| Vmware | Horizon View | 6.0.2 |
| Vmware | Horizon View | 6.1 |
| Vmware | Horizon View | 6.1.1 |
| Vmware | Horizon View | 6.2 |
| Vmware | Horizon View | 6.2.1 |
| Vmware | Horizon View | 6.2.2 |
| Vmware | Horizon View | 6.2.3 |
| Vmware | Horizon View | 6.2.4 |
| Vmware | Horizon View | 7.0 |
| Vmware | Unified Access Gateway | 2.5 |
| Vmware | Unified Access Gateway | 2.5.1 |
| Vmware | Unified Access Gateway | 2.7 |
| Vmware | Unified Access Gateway | 2.7.2 |
| Vmware | Unified Access Gateway | 2.8 |
References
- http://www.securityfocus.com/bid/97914Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/97914Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-4907?
How severe is CVE-2017-4907?
How do I fix CVE-2017-4907?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-4900VMware Workstation Pro/Player 12.x before 12.5.3 contains a …
- CVE-2017-4901The drag-and-drop (DnD) function in VMware Workstation 12.x …
- CVE-2017-4902VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 w…8.8
- CVE-2017-4903VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 w…8.8
- CVE-2017-4904The XHCI controller in VMware ESXi 6.5 without patch ESXi650…8.8
- CVE-2017-4905VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 w…5.5
- CVE-2017-4908VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4909VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4910VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4911VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4912VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4913VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
Are you affected by CVE-2017-4907?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
