CVE-2018-6973
published 2018-08-15CVE-2018-6973: VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow…
PriorityP343high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.49%
39.1th percentile
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | fusion | < 10.1.3 | 10.1.3 |
| vmware | fusion | — | — |
| vmware | fusion_pro | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 14.0.0 < 14.1.3 | 14.1.3 |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m7mh-m68x-wqxx: VMware Workstation (14
ghsa_unreviewed·2022-05-14
CVE-2018-6973 [HIGH] CWE-787 GHSA-m7mh-m68x-wqxx: VMware Workstation (14
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.
VMware
VMware Workstation and Fusion updates address an out-of-bounds write issue
vendor_vmware·2018-08-14·CVSS 8.8
CVE-2018-6973 [HIGH] VMware Workstation and Fusion updates address an out-of-bounds write issue
VMSA-2018-0022: VMware Workstation and Fusion updates address an out-of-bounds write issue
Workstation and Fusion e1000 device out-of-bounds write vulnerability VMware Workstation and Fusion contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host. VMware would like to thank Anonymous working with Trend Micro's Zero Day Initiative for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6973 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch Mitigation/ Workaround VMware Produ
No detection rules found.
No writeups or analysis indexed.
2018-08-15
Published