cbcvebase.
CVE-2018-6972
published 2018-07-25

CVE-2018-6972: VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG)…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Affected

21 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion
vmwarefusion>= 10.0 < 10.1.210.1.2
vmwarefusion_pro
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_horizon
vmwarevmware_vrealize
vmwarevmware_vsphere
vmwarevmware_workstation
vmwareworkstation
vmwareworkstation>= 14.0 < 14.1.214.1.2
vmwareworkstation_player
vmwareworkstation_pro