CVE-2018-6982
published 2018-12-04CVE-2018-6982: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual…
PriorityP424medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.45%
36.5th percentile
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | >= 10.0.0 < 10.1.4 | 10.1.4 |
| vmware | fusion_pro | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 14.0.0 < 14.1.4 | 14.1.4 |
| vmware | workstation_player | — | — |
| vmware | workstation_pro | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pwjr-88cq-mmr3: VMware ESXi 6
ghsa_unreviewed·2022-05-13
CVE-2018-6982 [MEDIUM] CWE-908 GHSA-pwjr-88cq-mmr3: VMware ESXi 6
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
VMware
VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage
vendor_vmware·2018-11-09·CVSS 8.8
CVE-2018-6981 [HIGH] VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage
VMSA-2018-0027: VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage
VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage. 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro, Fusion (Fusion)3. Problem Description a. vmxnet3 uninitialized stack memory usage VMware ESXi, Fusion and Workstation contain uninitialized stack memory usage in the vmxnet3 virtual network adapter. This issue may allow a guest to execute code on the host. The issue is present if vmxnet3 is enabled. Non vmxnet3 virtual adapters are not affected by this issue. VMware would like to thank the organizers of GeekPwn2018 and security researchers Zhangyanyu of Chaitin Tech and SmallerDragon for repo
No detection rules found.
No public exploits indexed.
Tenable
VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
blogs_tenable·2018-11-12·CVSS 8.8
[HIGH] VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
blogs_tenable·2018-11-12·CVSS 8.8
CVE-2018-6981 [HIGH] VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
Blog / Cyber Exposure Alerts
Subscribe
# VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
Satnam Narang
November 12, 2018
2 Min Read
VMware issued an advisory about two uninitialized stack memory usage bugs and has released patches and updates for some versions of the affected software.
## Background
On November 9, VMware published a security advisory to address a Guest-to-Host Escape vulnerability affecting VMware ESXi, Workstation and Fusion. The vulnerability was discovered and released by a security researcher at GeekPwn 2018, an annual security conference in Shanghai, China which took place in late October 2018. The researcher reported the vulnerability to VMware through GeekPwn.
Source: @ChaitinTech on Twitter.
## Vulnerability details
2018-12-04
Published