CVE-2018-6957: Medium severity VMware Workstation Pro vulnerability
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Workstationto a version that resolves this vulnerability.Fixed in 14.1.1 - Upgrade
Upgrade
VMware Fusionto a version that resolves this vulnerability.Fixed in 10.1.1 - Upgrade
Upgrade
VMware Fusionto a version that resolves this vulnerability.Fixed in 8.x - Configuration
VNC must be manually enabled for exploitation to be possible on Workstation and Fusion; keep VNC disabled to prevent triggering the denial-of-service via many VNC sessions.
VNC in VMware Workstation/Fusion VNC session availability (VNC enabled/disabled) = disabled
Event History
Frequently Asked Questions
What is CVE-2018-6957?
CVE-2018-6957 is a denia...
What software is affected by CVE-2018-6957?
VMware Workstation Pro (14.x before 14.1.1, 12.x) and VMware Fusion (10.x before 10.1.1 and 8.x) are affected.
How can CVE-2018-6957 be exploited?
CVE-2018-6957 can be exploited by opening a large number of VNC sessions, provided that VNC is manually enabled on VMware Workstation and Fusion.
What is the severity of CVE-2018-6957?
CVE-2018-6957 has a severity rating of medium (5.3).
Where can I find more information about CVE-2018-6957?
You can find more information about CVE-2018-6957 at the following references: [1](http://www.securityfocus.com/bid/103431), [2](http://www.securitytracker.com/id/1040539), [3](https://www.vmware.com/security/advisories/VMSA-2018-0008.html)