#VU13517 Out-of-bounds read in VMware, Inc products - CVE-2018-6965
Published: June 29, 2018
Vulnerability identifier: #VU13517
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-6965
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
VMware ESXi
VMware Fusion
VMware Workstation
VMware ESXi
VMware Fusion
VMware Workstation
Software vendor:
VMware, Inc
VMware, Inc
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition.
The weakness exists due to out-of-bounds read in the shader translator. A remote attacker can gain access to arbitrary data or cause the application to crash.
The weakness exists due to out-of-bounds read in the shader translator. A remote attacker can gain access to arbitrary data or cause the application to crash.
Remediation
Update VMware Fusion to version 10.1.2.
Update VMware Workstation to version 14.1.2.
Update VMware Workstation to version 14.1.2.