CVE-2018-6977: Medium severity VMware ESXi vulnerability
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6977?
CVE-2018-6977 is classified as a denial-of-service vulnerability that affects multiple VMware products.
How do I fix CVE-2018-6977?
To fix CVE-2018-6977, update your VMware ESXi, Workstation, or Fusion to the latest patched version.
What products are affected by CVE-2018-6977?
CVE-2018-6977 affects VMware ESXi 6.0, 6.5, 6.7, Workstation 14.x and 15.x, and Fusion 10.x and 11.x.
What is the impact of exploiting CVE-2018-6977?
Exploiting CVE-2018-6977 can lead to an unresponsive virtual machine due to an infinite loop in a 3D-rendering shader.
Who can exploit CVE-2018-6977?
CVE-2018-6977 can be exploited by an attacker with normal user privileges within the affected virtual machine.