CVE-2018-6977

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/10/2018
Last modified:
03/10/2019

Description

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:vmware:esxi:6.0:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 14.0.0 (including) 14.1.5 (including)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.2 (including)
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 10.0.0 (including) 10.1.5 (including)
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 11.0.0 (including) 11.0.2 (including)