CVE-2018-6981
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to execute code on the host.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- vmware/workstation · vmware/fusion · vmware/esxi
- Source
- security@vmware.com
References
- http://www.securityfocus.com/bid/105881Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042054Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042055Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2018-0027.htmlVendor Advisory
- http://www.securityfocus.com/bid/105881Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042054Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042055Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2018-0027.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.