First published: Fri Jul 13 2018(Updated: )
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Tools | <10.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6969 is a vulnerability in VMware Tools (10.x and prior before 10.3.0) that allows attackers to escalate their privileges on the guest VMs or disclose sensitive information.
CVE-2018-6969 has a severity rating of 7 (high).
The affected software version of CVE-2018-6969 is VMware Tools 10.x and prior before 10.3.0.
CVE-2018-6969 can be exploited by successfully exploiting an out-of-bounds read vulnerability in the HGFS component of VMware Tools, which may allow attackers to escalate privileges or disclose sensitive information.
To fix CVE-2018-6969, update VMware Tools to version 10.3.0 or later, as this version contains the necessary patches to address the vulnerability.