First published: Thu Jun 28 2018(Updated: )
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6967.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion Pro | >=10.0<10.1.2 | |
macOS Yosemite | ||
VMware Workstation | >=14.0<14.1.2 | |
VMware ESXi | =6.7 | |
VMware ESXi | =6.7-670-201806001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6966 is classified as a medium severity vulnerability.
To fix CVE-2018-6966, update VMware ESXi to version 6.7-670-201806401-BG or later, and VMware Workstation and Fusion to versions 14.1.2 or later.
CVE-2018-6966 can be exploited for information disclosure or potentially allow attackers with normal user privileges to read sensitive data.
CVE-2018-6966 affects VMware ESXi 6.7, Workstation 14.x before 14.1.2, and Fusion 10.x before 10.1.2.
While not classified as critical, CVE-2018-6966 poses a notable risk due to potential information disclosure.