CVE-2018-6957
published 2018-03-15CVE-2018-6957: VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by…
PriorityP425medium5.3CVSS 3.0
AVNACHPRLUINSUCNINAH
EPSS
1.62%
73.6th percentile
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | >= 10.0 < 10.1.1 | 10.1.1 |
| vmware | fusion_pro | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
| vmware | workstation_player | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxf5-fpm2-g9fg: VMware Workstation (14
ghsa_unreviewed·2022-05-13
CVE-2018-6957 [MEDIUM] GHSA-vxf5-fpm2-g9fg: VMware Workstation (14
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
VMware
Workstation and Fusion updates address a denial-of-service vulnerability
vendor_vmware·2018-03-15·CVSS 5.3
CVE-2018-6957 [MEDIUM] Workstation and Fusion updates address a denial-of-service vulnerability
VMSA-2018-0008: Workstation and Fusion updates address a denial-of-service vulnerability
Workstation and Fusion updates address a denial-of-service vulnerability 2. Relevant Products VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description Denial-of-service vulnerability through VNC VMware Workstation and Fusion contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled. VMware would like to thank Lilith Wyatt of Cisco Talos for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6957 to this issue. Column 5 of the
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: VMWare VNC Vulnerabilities
blogs_talos·2017-12-19·CVSS 8.8
CVE-2018-6957 [HIGH] Vulnerability Spotlight: VMWare VNC Vulnerabilities
UPDATE 03/15/2018: Added details for Talos-2017-0376/CVE-2018-6957 which has been recently patched.
Today, Talos is disclosing a pair of vulnerabilities in the VNC implementation used in VMWare's products that could result in code execution. VMWare implements VNC for its remote management, remote access, and automation purposes in VMWare products including Workstation, Player, and ESXi which share a common VMW VNC code base. The vulnerabilities manifest themselves in a way that would allow an attacker to initiate of VNC session causing the vulnerabilities to be triggered. Talos has coordinated with VMWare to ensure the issue was disclosed responsibly and patched by the vendor. Additionally, Talos has developed Snort signatures that can detect attempts to exploit these vulnerabilities.
Th
Talos
Vulnerability Spotlight: VMWare VNC Vulnerabilities
blogs_talos·2017-12-19·CVSS 8.8
CVE-2018-6957 [HIGH] Vulnerability Spotlight: VMWare VNC Vulnerabilities
## Vulnerability Spotlight: VMWare VNC Vulnerabilities
UPDATE 03/15/2018: Added details for Talos-2017-0376/CVE-2018-6957 which has been recently patched.
Today, Talos is disclosing a pair of vulnerabilities in the VNC implementation used in VMWare's products that could result in code execution. VMWare implements VNC for its remote management, remote access, and automation purposes in VMWare products including Workstation, Player, and ESXi which share a common VMW VNC code base. The vulnerabilities manifest themselves in a way that would allow an attacker to initiate of VNC session causing the vulnerabilities to be triggered. Talos has coordinated with VMWare to ensure the issue was disclosed responsibly and patched by the vendor. Additionally, Talos has developed Snort signatures that c
2018-03-15
Published