VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1039368 | vdb entry third party advisory |
http://www.securityfocus.com/bid/100842 | vdb entry third party advisory |
https://www.vmware.com/security/advisories/VMSA-2017-0015.html | vendor advisory |
http://www.securitytracker.com/id/1039367 | vdb entry third party advisory |