CVE-2017-4913
Last modified
CVE-2017-4913 is a vulnerability of currently unknown severity. VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Horizon View | 4.0 |
| Vmware | Horizon View | 4.1 |
| Vmware | Horizon View | 4.2 |
| Vmware | Horizon View | 4.3 |
| Vmware | Workstation | 12.0 |
| Vmware | Workstation | 12.0.1 |
| Vmware | Workstation | 12.1 |
| Vmware | Workstation | 12.1.1 |
| Vmware | Workstation | 12.5 |
| Vmware | Workstation | 12.5.1 |
| Vmware | Workstation | 12.5.2 |
References
- http://www.securityfocus.com/bid/97920Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/97920Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-4913?
How severe is CVE-2017-4913?
How do I fix CVE-2017-4913?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-4907VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to …
- CVE-2017-4908VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4909VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4910VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4911VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4912VMware Workstation (12.x prior to 12.5.3) and Horizon View C…
- CVE-2017-4914VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, an…
- CVE-2017-4915VMware Workstation Pro/Player contains an insecure library l…
- CVE-2017-4916VMware Workstation Pro/Player contains a NULL pointer derefe…
- CVE-2017-4917VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, an…
- CVE-2017-4918VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0)…
- CVE-2017-4919VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users wit…
Are you affected by CVE-2017-4913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
