Stack-based buffer overflow in VMware ESXi - CVE-2018-6982

 

Stack-based buffer overflow in VMware ESXi - CVE-2018-6982

Published: November 9, 2018


Vulnerability identifier: #VU15787
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6982
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.

The weakness exists due to uninitialized stack memory usage in the vmxnet3 virtual network adapter. A remote attacker can trigger memory corruption if vmxnet3 is enabled and access arbitrary data.


Affected software

VMware ESXi
EMC Integrated Data Protection Appliance
Release Certification Matrix (RCM)

How to mitigate CVE-2018-6982

Install update from vendor's website.

EMC Integrated Data Protection Appliance - update to 2.3
Release Certification Matrix (RCM) - addressed in versions 3.0.12.1, 3.2.6.1, 3.3.3.1

External References

Related Security Bulletins