CVE-2018-6973: High severity vmware fusion vulnerability
Published Aug 15, 2018
·Updated
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.
Affected Software
2 affected components
VMware Fusion>10.0.0<10.1.3
VMware Workstation>=14.0.0<14.1.3
Event History
Aug 15, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-6973?
CVE-2018-6973 is considered a critical vulnerability due to its potential to allow code execution on the host system.
2
How do I fix CVE-2018-6973?
To fix CVE-2018-6973, update VMware Workstation to version 14.1.3 or later and VMware Fusion to version 10.1.3 or later.
3
What types of systems are affected by CVE-2018-6973?
CVE-2018-6973 affects VMware Workstation versions 14.0.0 to 14.1.2 and VMware Fusion versions 10.0.0 to 10.1.2.
4
Can CVE-2018-6973 be exploited remotely?
Yes, CVE-2018-6973 can be exploited by a guest virtual machine to execute arbitrary code on the host machine.
5
What component of VMware products is impacted by CVE-2018-6973?
CVE-2018-6973 impacts the e1000 network device within VMware Workstation and Fusion.