Heap-based buffer overflow in VMware, Inc products - CVE-2017-4933
Published: December 22, 2017
VMware ESXi
VMware Fusion
VMware Workstation
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the remote management functionality due to improper handling of Virtual Network Computing (VNC) packets. A remote attacker can send a series of VNC packets, cause heap-based buffer overflow to execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.