VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.
Conclusion & alert: CVE-2017-4910 is rated Moderate Risk (40.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.08%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2023-03-07 | 1.36% | 0.08% | -1.29% |
| 2 | 2022-02-04 | 2.26% | 1.36% | -0.89% |
| 3 | 2021-04-14 | — | 2.26% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.0 | HIGH |
|
1.1 | 6.0 | [email protected] |
| 6.9 | 2.0 | MEDIUM |
|
3.4 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| vmware | horizon_view | 4.0 | cpe:2.3:a:vmware:horizon_view:4.0:*:*:*:*:*:*:* |
| vmware | horizon_view | 4.1 | cpe:2.3:a:vmware:horizon_view:4.1:*:*:*:*:*:*:* |
| vmware | horizon_view | 4.2 | cpe:2.3:a:vmware:horizon_view:4.2:*:*:*:*:*:*:* |
| vmware | horizon_view | 4.3 | cpe:2.3:a:vmware:horizon_view:4.3:*:*:*:*:*:*:* |
| vmware | workstation | 12.0 | cpe:2.3:a:vmware:workstation:12.0:*:*:*:*:*:*:* |
| vmware | workstation | 12.0.1 | cpe:2.3:a:vmware:workstation:12.0.1:*:*:*:*:*:*:* |
| vmware | workstation | 12.1 | cpe:2.3:a:vmware:workstation:12.1:*:*:*:*:*:*:* |
| vmware | workstation | 12.1.1 | cpe:2.3:a:vmware:workstation:12.1.1:*:*:*:*:*:*:* |
| vmware | workstation | 12.5 | cpe:2.3:a:vmware:workstation:12.5:*:*:*:*:*:*:* |
| vmware | workstation | 12.5.1 | cpe:2.3:a:vmware:workstation:12.5.1:*:*:*:*:*:*:* |
| vmware | workstation | 12.5.2 | cpe:2.3:a:vmware:workstation:12.5.2:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/97913 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1038280 | |
| http://www.securitytracker.com/id/1038281 | |
| http://www.vmware.com/security/advisories/VMSA-2017-0008.html | Vendor Advisory |