Out-of-bounds write in VMware Workstation and VMware Fusion - CVE-2018-6973

 

Out-of-bounds write in VMware Workstation and VMware Fusion - CVE-2018-6973

Published: August 14, 2018 / Updated: August 15, 2018


Vulnerability identifier: #VU14413
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-6973
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: VMware, Inc
Affected software:
VMware Workstation
VMware Fusion

Detailed vulnerability description

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists due to out-of-bounds write in the e1000 device. An adjacent attacker can trigger memory corruption and execute arbitrary code withe elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2018-6973

Update Workstation to version 14.1.3.
Update Fusion to version 10.1.3.

Sources