vendor:
Workstation Pro/Player
by:
Borja Merino
7,2
CVSS
HIGH
NULL pointer dereference
476
CWE
Product Name: Workstation Pro/Player
Affected Version From: 12.x
Affected Version To: 12.x
Patch Exists: YES
Related CWE: 2017-4916 (VMSA-2017-0009)
CPE: a:vmware:workstation_player:12.5.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 Pro and Windows 7 Pro (SP1)
2017
NULL pointer dereference vulnerability in vstor2 driver (VMware Workstation Pro/Player)
This p0c produces a BSOD by sending a specific IOCTL code to the vstor2_mntapi20_shared device driver due to a double call to IofCompleteRequest (generating a MULTIPLE_IRP_COMPLETE_REQUESTS bug check)
Mitigation:
Update to the latest version of VMware Workstation Pro/Player 12.x