cbcvebase.
CVE-2018-6982
published 2018-12-04

CVE-2018-6982: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual…

PriorityP424medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.45%
36.5th percentile
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.

Affected

15 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion
vmwarefusion>= 10.0.0 < 10.1.410.1.4
vmwarefusion_pro
vmwarevmware_esxi
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_vsphere
vmwarevmware_workstation
vmwareworkstation
vmwareworkstation>= 14.0.0 < 14.1.414.1.4
vmwareworkstation_player
vmwareworkstation_pro

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.