CVE-2018-6969
published 2018-07-13CVE-2018-6969: VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information…
PriorityP428high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.40%
31.7th percentile
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | tools | < 10.3.0 | 10.3.0 |
| vmware | vmware_tools | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc3q-9h28-r994: VMware Tools (10
ghsa_unreviewed·2022-05-14
CVE-2018-6969 [HIGH] CWE-125 GHSA-qc3q-9h28-r994: VMware Tools (10
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled.
Red Hat
open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
vendor_redhat·2018-07-16·CVSS 7.0
CVE-2018-6969 [HIGH] CWE-125 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled.
Package: open-vm-tools (Red Hat Enterprise Linux 7) - Not affected
Package: open-vm-tools (Red Hat Enterprise Linux 8) - Not affected
VMware
VMware Tools update addresses an out-of-bounds read vulnerability
vendor_vmware·2018-07-12·CVSS 7.0
CVE-2018-6969 [HIGH] VMware Tools update addresses an out-of-bounds read vulnerability
VMSA-2018-0017: VMware Tools update addresses an out-of-bounds read vulnerability
VMware Tools update addresses an out-of-bounds read vulnerability 2. Relevant Products VMware Tools for Windows 3. Problem Description VMware Tools Shared Folders out-of-bounds read vulnerability VMware Tools for Windows contains an out-of-bounds read vulnerability in the Shared Folders feature. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. Note: In order to be able to exploit this issue, Shared Folders feature must be enabled. This issue only affects Windows VMs running on VMware Workstation or Fusion. Products that do not allow the Shared Folders feature to be enabled are not affected. VMware would like to than
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation [fedora-all]
bugzilla·2018-07-19·CVSS 7.0
CVE-2018-6969 [HIGH] CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation [fedora-all]
CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
Bugzilla
CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
bugzilla·2018-07-19·CVSS 7.0
CVE-2018-6969 [HIGH] CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled.
External Reference:
https://www.vmware.com/security/advisories/VMSA-2018-0017.html
Discussion:
Created open-vm-tools tracking bugs for this issue:
Affects: epel-6 [bug 1603050]
Affects: fedora-all [bug 1603049]
---
This advisory does not affect open-vm-tools, because it is about a Windows specific issue. I'm copying a note from https://www.vmware.com/
Bugzilla
CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation [epel-6]
bugzilla·2018-07-19·CVSS 7.0
CVE-2018-6969 [HIGH] CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation [epel-6]
CVE-2018-6969 open-vm-tools: Out-of-bounds read in HGFS allows for information disclosure or potential privilege escalation [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
2018-07-13
Published