CVE-2018-6977
published 2018-10-09CVE-2018-6977: VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a…
PriorityP424medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.43%
34.6th percentile
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | 10.0.0 – 10.1.5 | — |
| vmware | fusion | 11.0.0 – 11.0.2 | — |
| vmware | fusion_pro | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | 14.0.0 – 14.1.5 | — |
| vmware | workstation | 15.0.0 – 15.0.2 | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation, and Fusion workarounds address a denial-of-service vulnerability
vendor_vmware
CVE-2018-6977 [HIGH] VMware ESXi, Workstation, and Fusion workarounds address a denial-of-service vulnerability
VMSA-2018-0025: VMware ESXi, Workstation, and Fusion workarounds address a denial-of-service vulnerability
VMware ESXi, Workstation, and Fusion workarounds address a denial-of-service vulnerability 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro, Fusion (Fusion)3. Problem Description Denial-of-service vulnerability in 3D-acceleration feature VMware ESXi, Workstation and Fusion contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive. Because many graphics API's and hardw
GHSA
GHSA-29m2-93j9-hrcp: VMware ESXi (6
ghsa_unreviewed·2022-05-13
CVE-2018-6977 [MEDIUM] CWE-835 GHSA-29m2-93j9-hrcp: VMware ESXi (6
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: VMWare Workstation DoS Vulnerability
blogs_talos·2018-10-09·CVSS 6.5
CVE-2018-6977 [MEDIUM] Vulnerability Spotlight: VMWare Workstation DoS Vulnerability
Today, Cisco Talos is disclosing a vulnerability in VMware Workstation that could result in denial of service. VMware Workstation is a widely used virtualization platform designed to run alongside a normal operating system, allowing users to use both virtualized and physical systems concurrently.
### TALOS-2018-0589
Discovered by Piotr Bania of Cisco Talos
TALOS-2018-0589 / CVE-2018-6977 is an exploitable denial-of-service (DoS) vulnerability in the VMware Workstation 14 software. The vulnerability lies in the pixel shader utilized by VMware Workstation and can be triggered by supplying a malformed pixel shader in either text or binary form inside a VMware guest operating system. This vulnerability can be triggered from VMware guest or VMware hosts and results in a process crashing leadi
Talos
Vulnerability Spotlight: VMWare Workstation DoS Vulnerability
blogs_talos·2018-10-09·CVSS 6.5
CVE-2018-6977 [MEDIUM] Vulnerability Spotlight: VMWare Workstation DoS Vulnerability
## Vulnerability Spotlight: VMWare Workstation DoS Vulnerability
Today, Cisco Talos is disclosing a vulnerability in VMware Workstation that could result in denial of service. VMware Workstation is a widely used virtualization platform designed to run alongside a normal operating system, allowing users to use both virtualized and physical systems concurrently.
## TALOS-2018-0589
Discovered by Piotr Bania of Cisco Talos TALOS-2018-0589 / CVE-2018-6977 is an exploitable denial-of-service (DoS) vulnerability in the VMware Workstation 14 software. The vulnerability lies in the pixel shader utilized by VMware Workstation and can be triggered by supplying a malformed pixel shader in either text or binary form inside a VMware guest operating system. This vulnerability can be triggered from VMw
http://www.securityfocus.com/bid/105549http://www.securitytracker.com/id/1041821http://www.securitytracker.com/id/1041822https://www.vmware.com/security/advisories/VMSA-2018-0025.htmlhttp://www.securityfocus.com/bid/105549http://www.securitytracker.com/id/1041821http://www.securitytracker.com/id/1041822https://www.vmware.com/security/advisories/VMSA-2018-0025.html
2018-10-09
Published