CVE-2018-6966
published 2018-07-09CVE-2018-6966: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in…
PriorityP343high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
2.26%
81.0th percentile
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6967.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | fusion | >= 10.0 < 10.1.2 | 10.1.2 |
| vmware | fusion_pro | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | >= 14.0 < 14.1.2 | 14.1.2 |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rfp7-37cm-29c6: VMware ESXi (6
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-6967 [HIGH] CWE-125 GHSA-rfp7-37cm-29c6: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6966.
GHSA
GHSA-9mxp-fhjm-5wwh: VMware ESXi (6
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-6966 [HIGH] CWE-125 GHSA-9mxp-fhjm-5wwh: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6967.
GHSA
GHSA-8chp-q824-m353: VMware ESXi (6
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-6965 [HIGH] CWE-125 GHSA-8chp-q824-m353: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6966 and CVE-2018-6967.
VMware
VMware ESXi, Workstation, and Fusion updates address multiple out-of-bounds read vulnerabilities
vendor_vmware·2018-06-28·CVSS 8.1
CVE-2018-6965 [HIGH] VMware ESXi, Workstation, and Fusion updates address multiple out-of-bounds read vulnerabilities
VMSA-2018-0016: VMware ESXi, Workstation, and Fusion updates address multiple out-of-bounds read vulnerabilities
VMware ESXi, Workstation, and Fusion updates address multiple out-of-bounds read vulnerabilities 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro, Fusion (Fusion) 3. Problem Description ESXi, Workstation, and Fusion multiple out-of-bounds read vulnerabilities VMware ESXi, Workstation, and Fusion contain multiple out-of-bounds read vulnerabilities in the shader translator. Successful exploitation of these issues may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs. VMware would like to thank RanchoIce of Tencent ZhanluLab (CVE-2018-6965, CVE-2018-6966, CVE-2018-6967
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-09
Published