Rapid7 Vulnerability & Exploit Database

VMSA-2018-0026: VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability (CVE-2018-6974)

Back to Search

VMSA-2018-0026: VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability (CVE-2018-6974)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
10/16/2018
Created
03/19/2019
Added
10/19/2018
Modified
02/15/2019

Description

VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.

Solution(s)

  • vmware-esxi60-upgrade-8967301
  • vmware-esxi65-upgrade-9298722
  • vmware-esxi67-upgrade-10176879

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;