VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96771 | third party advisory vdb entry |
http://www.vmware.com/security/advisories/VMSA-2017-0003.html | patch vendor advisory |
http://www.securitytracker.com/id/1037979 | vdb entry |