First published: Tue Oct 09 2018(Updated: )
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ESXi | =6.0 | |
VMware ESXi | =6.5 | |
VMware ESXi | =6.7 | |
VMware Workstation | >=14.0.0<=14.1.5 | |
VMware Workstation | >=15.0.0<=15.0.2 | |
VMware Fusion Pro | >=10.0.0<=10.1.5 | |
VMware Fusion Pro | >=11.0.0<=11.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6977 is classified as a denial-of-service vulnerability that affects multiple VMware products.
To fix CVE-2018-6977, update your VMware ESXi, Workstation, or Fusion to the latest patched version.
CVE-2018-6977 affects VMware ESXi 6.0, 6.5, 6.7, Workstation 14.x and 15.x, and Fusion 10.x and 11.x.
Exploiting CVE-2018-6977 can lead to an unresponsive virtual machine due to an infinite loop in a 3D-rendering shader.
CVE-2018-6977 can be exploited by an attacker with normal user privileges within the affected virtual machine.