First published: Wed Aug 15 2018(Updated: )
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion Pro | >10.0.0<10.1.3 | |
VMware Workstation | >=14.0.0<14.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6973 is considered a critical vulnerability due to its potential to allow code execution on the host system.
To fix CVE-2018-6973, update VMware Workstation to version 14.1.3 or later and VMware Fusion to version 10.1.3 or later.
CVE-2018-6973 affects VMware Workstation versions 14.0.0 to 14.1.2 and VMware Fusion versions 10.0.0 to 10.1.2.
Yes, CVE-2018-6973 can be exploited by a guest virtual machine to execute arbitrary code on the host machine.
CVE-2018-6973 impacts the e1000 network device within VMware Workstation and Fusion.