PT-2018-17858 · Vmware · Vmware Esxi+2

Publicado

2018-12-04

·

Atualizado

2022-02-03

·

CVE-2018-6981

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware ESXi versions 6.0 without ESXi600-201811401-BG VMware ESXi versions 6.5 without ESXi650-201811301-BG VMware ESXi versions 6.7 without ESXi670-201811401-BG VMware Workstation versions 14.1.3 and below VMware Workstation version 15 VMware Fusion versions 10.1.3 and below VMware Fusion version 11
Description The issue concerns uninitialized stack memory usage in the vmxnet3 virtual network adapter. This may allow a guest to execute code on the host.
Recommendations For VMware ESXi 6.0, apply the ESXi600-201811401-BG patch to resolve the issue. For VMware ESXi 6.5, apply the ESXi650-201811301-BG patch to resolve the issue. For VMware ESXi 6.7, apply the ESXi670-201811401-BG patch to resolve the issue. For VMware Workstation 14.1.3 and below, update to a version above 14.1.3 to resolve the issue. For VMware Workstation 15, a specific fix is not mentioned, so consider updating to a newer version if available. For VMware Fusion 10.1.3 and below, update to a version above 10.1.3 to resolve the issue. For VMware Fusion 11, a specific fix is not mentioned, so consider updating to a newer version if available.

Exploit

Correção

Use of Uninitialized Resource

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6981

Produtos afetados

Vmware Esxi
Vmware Fusion
Vmware Workstation