CVE-2017-4935
Last modified
CVE-2017-4935 is a vulnerability of currently unknown severity. VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View Client.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Workstation | 12.0.0 |
| Vmware | Workstation | 12.0.1 |
| Vmware | Workstation | 12.1 |
| Vmware | Workstation | 12.1.1 |
| Vmware | Workstation | 12.5 |
| Vmware | Workstation | 12.5.1 |
| Vmware | Workstation | 12.5.2 |
| Vmware | Workstation | 12.5.3 |
| Vmware | Workstation | 12.5.4 |
| Vmware | Workstation | 12.5.5 |
| Vmware | Workstation | 12.5.6 |
| Vmware | Workstation | 12.5.7 |
| Vmware | Horizon View | 4.0.0 |
| Vmware | Horizon View | 4.0.1 |
| Vmware | Horizon View | 4.1 |
| Vmware | Horizon View | 4.2 |
| Vmware | Horizon View | 4.3 |
| Vmware | Horizon View | 4.4 |
| Vmware | Horizon View | 4.5 |
| Vmware | Horizon View | 4.6 |
References
- http://www.securityfocus.com/bid/101902Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039835Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039836Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2017-0018.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/101902Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039835Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039836Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2017-0018.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-4935?
How severe is CVE-2017-4935?
How do I fix CVE-2017-4935?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-4929VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) …
- CVE-2017-4930VMware AirWatch Console 9.x prior to 9.2.0 contains a vulner…
- CVE-2017-4931VMware AirWatch Console 9.x prior to 9.2.0 contains a vulner…
- CVE-2017-4932VMware AirWatch Launcher for Android prior to 3.2.2 contains…
- CVE-2017-4933VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (…8.8
- CVE-2017-4934VMware Workstation (12.x before 12.5.8) and Fusion (8.x befo…
- CVE-2017-4936VMware Workstation (12.x before 12.5.8) and Horizon View Cli…
- CVE-2017-4937VMware Workstation (12.x before 12.5.8) and Horizon View Cli…
- CVE-2017-4938VMware Workstation (12.x before 12.5.8) and Fusion (8.x befo…
- CVE-2017-4939VMware Workstation (12.x before 12.5.8) installer contains a…
- CVE-2017-4940The ESXi Host Client in VMware ESXi (6.5 before ESXi650-2017…6.1
- CVE-2017-4941VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-20…8.8
Are you affected by CVE-2017-4935?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
