CVE-2018-6974
published 2018-10-16CVE-2018-6974: VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and…
PriorityP343high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.47%
38.0th percentile
VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | >= 10.0 < 10.1.3 | 10.1.3 |
| vmware | fusion_pro | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 14.0 < 14.1.3 | 14.1.3 |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability
vendor_vmware·2018-10-16·CVSS 8.8
CVE-2018-6974 [HIGH] VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability
VMSA-2018-0026: VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability
VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro, Fusion (Fusion) 3. Problem Description Out-of-bounds read vulnerability in SVGA Device VMware ESXi, Fusion and Workstation contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host. VMware would like to thank Anonymous working with Trend Micro's Zero Day Initiative for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6974 to this issue. Column 5 of t
GHSA
GHSA-5vq3-72qx-fm2c: VMware ESXi (6
ghsa_unreviewed·2022-05-14
CVE-2018-6974 [HIGH] CWE-125 GHSA-5vq3-72qx-fm2c: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105660http://www.securitytracker.com/id/1041875http://www.securitytracker.com/id/1041876https://www.vmware.com/security/advisories/VMSA-2018-0026.htmlhttp://www.securityfocus.com/bid/105660http://www.securitytracker.com/id/1041875http://www.securitytracker.com/id/1041876https://www.vmware.com/security/advisories/VMSA-2018-0026.html
2018-10-16
Published