CERT-In Advisory
CIAD-2017-0052
Multiple Vulnerabilities in VMWARE products
Original Issue Date: November 22, 2017
Severity Rating: High
Software Affected
- VM Ware workstation versions 12.x
- VM Ware fusion versions 8.x
Overview
Multiple vulnerabilities have been reported in VMWare Products which could allow an attacker to obtain user access privileges, execute arbitrary code or cause Denial of Service (Dos) conditions on the host machine.
Description
1. Heap buffer-overflow vulnerability
(
CVE-2017-4934
)
This vulnerability exists in the VMNAT service of VMWare workstation due to an unspecified condition. A local attacker could exploit this vulnerability by triggering a heap-based buffer overflow condition resulting in execution of arbitrary code on the host system. Successful exploitation of this vulnerability a local attacker could use to conduct further attacks.
2. Out-of-bounds write vulnerability
(
CVE-2017-4935
)
This vulnerability exists in JPEG2000 parser in the TPView.dll file of VMWare workstation due to insufficient bounds checks performed by the affected software. A local attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service (DoS) condition on the guest operating system.
Note: Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation.
3. Out-of-Bounds Memory Access Vulnerabilities
(
CVE-2017-4936
CVE-2017-4937
)
These vulnerabilities exist in the JPEG2000 parser in the TPView.dll file of VMWare workstation due to an error while parsing malicious image files by the affected software. A local attacker could exploit these vulnerabilities by persuading a user on a targeted guest operating system to open a malicious image file. Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code within a guest operating system or cause a denial of service (DoS) condition on the windows operating system that runs Workstation.
Note: Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation.
4. NULL Pointer Dereference Vulnerability
(
CVE-2017-4938
)
This vulnerability exists in VMware Workstation and Fusion due to the improper processing of remote procedure call (RPC) requests by the affected software. A local attacker could exploit this vulnerability via a crafted RPC request on the targeted guest operating system triggering a NULL pointer dereference condition. Successful exploitation of this vulnerability could allow the attacker with normal user privileges to cause the guest operating system to crash resulting in a DoS condition.
5. Local Code Execution Vulnerability
(
CVE-2017-4939
)
This vulnerability exists in VMware Workstation due to improper handling of DLL files when loaded by the application. A local attacker could exploit this vulnerability by loading malicious DLL files in Workstation installer. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate fixes as issued by vendor in
VMSA-2017-0018
Vendor Information
VMWare
https://www.vmware.com/in/security/advisories/VMSA-2017-0018.html
References
VMWare
https://www.vmware.com/in/security/advisories/VMSA-2017-0018.html
Security Tracker
https://www.securitytracker.com/id/1039835
CISCO
https://tools.cisco.com/security/center/viewAlert.x?alertId=55965
https://tools.cisco.com/security/center/viewAlert.x?alertId=55966
https://tools.cisco.com/security/center/viewAlert.x?alertId=55967
https://tools.cisco.com/security/center/viewAlert.x?alertId=55968
https://tools.cisco.com/security/center/viewAlert.x?alertId=55969
CVE Name
CVE-2017-4934
CVE-2017-4935
CVE-2017-4936
CVE-2017-4937
CVE-2017-4938
CVE-2017-4939
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|