cbcvebase.
CVE-2018-6977
published 2018-10-09

CVE-2018-6977: VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a…

PriorityP424medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.43%
34.6th percentile
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

Affected

16 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion
vmwarefusion10.0.0 – 10.1.5
vmwarefusion11.0.0 – 11.0.2
vmwarefusion_pro
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_vsphere
vmwarevmware_workstation
vmwareworkstation
vmwareworkstation14.0.0 – 14.1.5
vmwareworkstation15.0.0 – 15.0.2
vmwareworkstation_pro

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.