CVE Tools

Workstation Pro/player

6 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Workstation Pro/player. Use it to gauge the current risk picture and drill into individual advisories.

Workstation Pro/player CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Workstation Pro/player CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical117%
  • High233%
  • Medium350%

Latest CVEs

The 6 most recently published vulnerabilities affecting Workstation Pro/player.

  1. CVE-2017-4901The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to exe...9.9
  2. CVE-2017-4898VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable....8.8
  3. CVE-2017-4900VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with nor...5.5
  4. CVE-2017-4899VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read...4.7
  5. CVE-2017-4916VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privile...6.5
  6. CVE-2017-4915VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users t...7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store